HOPE Conference Audio
    Hackers On Planet Earth    

"So it was a bunch of smelly communists that took a break from playing with linux and looking at kiddy porn to gather together and (shock) relay their displeasure with the current politcal administration.  Yeah that sounds like fun.  Looks like that one Aaron guy didnt follow his own advice to 'shut the hell up, you don't know anything'.  Sounds like a really nice guy though."

    --- Anonymous Coward comment on Slashdot regarding H2K2.


"'You should try one of my body tune-ups,' says [John] Draper.  'It's a great energy boost.'  Indeed, he spends a good deal of time at the conference enticing young attendees back to his hotel room, where he offers full-contact 'stretching' sessions."

"... he won't give his handle - spent over $3,000 on a loft in Chelsea, insurance and other expenses, with plans to stage a $25-a-head orgy.  Instead, he says, 'the FBI investigated us; we were going to let some 17-year-olds come, so we were crossing a state line with the intent of having sex with a minor.'"

    --- Very interesting quotes in Hello, My Name Isn't ... while at H2K.


"... twenty-some years later he showed up in the San Francisco rave scene, a wild-looking man with gray hair and majorly f*cked-up teeth as a result of his prison experience.  He would stay up for days dancing and partying -- 'high on the energy', he said -- and trying to seduce young rave boys."

    --- Old quote about regular HOPE attendee "Captain Crunch" on 666.com.


"Suddenly pedophilia's relevant.  I'll give this some context.  All day friday and possibly all day saturday, (I can only vouch for friday) there seemed to be a team of legit journalists interviewing each panelist right after they got off the stage.  Except they were using a huge VHS camera.  And they weren't claiming to be a college class.  yadda yadda.  So anyhow it seems that each interview started out seeming quite legit but all of a sudden one of the lines of questioning became, 'do you have any evidence that Capn Crunch is a child molestor?  How about Emmanuel, I hear he hangs out with young boys.'  Then all of a sudden there are people all over here, all over the 2600.com irc chat, all over the slashdot threads spreading innuendo about Cap'n Crunch and Emmanuel."

    --- Some comments about $2600 Magazine, HOPE, "Captain Crunch," Steve Rombom, etc. which are posted at http://jewishdefense.org/rombom/.


"Actually, he has been seen doing the same things in public.  People notice it at meetings, and warn other teenagers.  A certain person named Hitman from NYC 2600 mention to someone to watch out for Emmanuel.  The kid went back to Emmanuel and had Hitman banned from HOPE 6.  I have always wonder where to of the teenagers that alway hung out with Emmanuel went.  RedHackt and Mr.Ohm disappeared from the scene after being close friends with Emmanuel."

"Maybe he was taken into custody because he was molested by Emmanuel Goldstein who is a suspected Pedophile."

"What is wrong with you people?  It's perfectly normal for a young boy to sleep in the same bed with a grown man."

"Probably just a ploy so that the Hope conference won't look so lame (as always) when compared to next week's Defcon conference"

    --- Some very interesting comments on the "Steve Rambam" arrest at HOPE Number Six which were posted in the Washington Post blog.


"Before joining Gist, David Ruderman designed software for web sites including Time, Money, Fortune, Entertainment Weekly.  At Time Warner's Pathfinder site, he developed web applications for community building, text retrieval, and content management.  He has developed electronic books for Times Mirror, and at Cold Spring Harbor Laboratory, Dave even worked on one of the first human-genome databases.  In 1984, Dave co-founded the hacker zine 2600.  He earned his Master Degree in Computer Science from the State University of New York at Stony Brook and holds a Bachelor Degree in Biology."

"Gist Communications is backed by Neptuno G.m.b.H., a subsidiary of Sal. Oppenheim Jr. & Compagnie, a private bank based in Cologne, Germany.  Neptuno's initial investment was several million dollars."

    --- September 16, 1996 quote in the New York Times about GIST Communications.  David Ruderman, one of the co-founders of $2600 Magazine, is GIST Communications' Vice President of Technology - and rich!


"Today he earns in the low six figures by advising executives on how to protect their companies from the current generation of ingenious but reckless geeks."

    --- Quote about HOPE keynote speaker Kevin Mitnick from Jonathan Littman in his Playboy article The Invisible Digital Man.  Nothing like using manufactured fear, history revisionism, and blatant lies to help you pull in six-figures a year.


"If [Steve] Rombom were tried and convicted as an adult, he would be subject technically, but not realistically, to a maximum term of imprisonment well over a hundred years."

    --- Quote from the United States District Court, S. D. New York, 1976 discussing Steve Rombom's jewish supremacist domestic terrorist activities in the 1970s.  Steve Rombom is often a keynote speaker at HOPE.  (Original)


"[Jello] Biafra has spent large amounts of time and money on attorney fees and court costs.  He continues to spend money on his appeal.  Although he lives in a 1.1-million-dollar house in the hills of San Francisco, he is asking others for donations to pay for his appeal.  The appeal will nevertheless reaffirm the court Judgment against him.  These resources could be used to maintain his record label, Alternative Tentacles.  But by continuing with his expensive, failing and misguided legal maneuvers, Alternative Tentacles may very well go under."

    --- Quote about commissar Eric Reed Boucher (Jello Biafra) from his fellow bandmates.  You just paid $100 to watch a bunch of gay millionaires tell you how to think!





HOPE: Hackers On Planet Earth





  1. (1994)  Robert Steele Keynote and Conference Introduction  - Robert Steele  
  2. (1994)  TDD Fundamentals  - Bernie S. (Ed Cummings)  
  3. (1994)  Fun With Pagers  - Thomas Icom  
    • Have you ever had the opportunity to monitor the pager of your choice, seeing each and every page as it comes over, alphanumeric included?  You will.  The entire city of New York is wide open and we'll demonstrate exactly how it's done.  More pager tricks and little-known facts will be presented.  Special appearance by Ixom (Ron Pinz).
    • AI Transcript
    • Pager Programming, Monitoring, and Applications

  4. (1994)  Control the World From Your PC  - Paul Bergsman  
    • Paul Bergsman will show attendees how to use a home computer to decode DTMF signals, control relays, lights, motors, and input burglary sensor data, monitor electric trains, and record voltage, temperature, or frequency.
    • DTMF Decoder  - Very detailed article on the hardware/software for building a computer-controlled (C64/V20) DTMF decoder, by Paul Bergsman  (Merion Station, Pennsylvania,, N3PSO)
    • Controlling The World with Your PC  by Paul Bergsman
    • AI Transcript

  5. (1994)  Cellular Phone Panel  - Bernie S., Jason Hillyard (Mr. Upsetter), Mark Lottor, and Andy Müeller-Maguhn  
    • O.K., how is it done, really?  We've all heard about cellular phone cloning but how many of us have had the guts to actually do it ourselves?  Actually, probably quite a few because it's relatively easy.  But, as with any technological trick, there is a multitude of misinformation being handed out.  That won't happen here as the true experts will be on hand to demonstrate cloning and answer questions.  We will show how cloning is not just for criminals and how you can clone a phone on your own PC!  Cellular software to do this will be made available for free!  You will also see first hand the risks of using a cellular phone.
    • AI Transcript

  6. (1994)  The New York City MetroCard  - Red Balaclava (Jeopardy Jim [Jim Vichench]), BillSF (Bill Squire)  
    • New York City has just introduced a brand new farecard system for mass transit, one unlike any other in the United States.  We have been gathering data on this system for some time now and hackers all over the world are trying to figure out ways of cracking it.  Unlike most other mass transit card systems, this one uses master databases.  We will read the cards, duplicate them, and make every attempt to defeat the system.  By the end of HOPE, we will have either cracked it or deemed it secure.  Your participation is encouraged.  We expect to have representatives of the Metropolitan Transit Authority on hand to answer questions and keep a nervous eye on us.
    • AI Transcript

  7. (1994)  European Hackers  - Rop Gonggrijp, Steffen Wernery, Hans, Andy Müeller-Maguhn  
    • Germany:  For many years now, Germany's Chaos Computer Club has been making headlines all over the world for all kinds of mischief.  But, as with all things, there is much much more to the story.  For the first time ever, the CCC will be in this country to answer questions and share information of all sorts.
    • Holland:  Although it's almost entirely in Dutch, Hack-Tic and the many people involved in its production have been the inspiration for hackers all over the planet.  If HOPE is half as successful as the two hacker congresses Hack-Tic has hosted (Galactic Hacker Party of 1989 and Hacking at the End of the Universe of 1993), it will be an incredible event.  Because of the far more relaxed atmosphere in Holland, hackers there are able to accomplish much more without all of the paranoia that is so abundant here.  We will hear their story and find out about all of the technological projects they're involved in.
    • AI Transcript

  8. (1994)  Social Engineering Panel  - Cheshire Catalyst (Robert Osband), Supernigger (Zohar Shif), and Evil Corley
    • By far one of the most effective ways of getting information is the art of social engineering.  You will see some live social engineering, get tips on what not to do, hear some great legendary tales from the masters, and listen to social engineering tapes of the past.  You are welcome to participate in our social engineering contest - we give you an operator and you go as far as you can.
    • AI Transcript

  9. (1994)  Lockpicking  - Paul Bergsman  
    • Everything from picks to electric drills to Simplex locks.
    • A talk on lockpicking by Paul Bergsman recorded with NO SOUND!  Hey, it was only our second day doing this and somebody rewired the sound board while we were all sleeping.  But maybe you can read lips or understand some of the diagrams.  And we did manage to get the audio figured out in the last four and a half minutes.  For the true collector.
    • AI Transcript

  10. (1994)  The National Identification Card  - Judi Clark, Bob Stratton, and Dave Banisar  
    • That's right, it may be coming a whole lot sooner than you EVER thought possible.  As you read this, there is a proposal in the works that would establish several states as a testing ground for mandatory national ID card.  We'll have the latest scoop on who's behind this and reaction from civil liberties and other groups.  We'll also be hearing from people in countries where national ID cards are already a reality and what it means to them.  Can it be stopped?  Should it be stopped?  Why you need to care.
    • AI Transcript

  11. (1994)  Linux  - Michael Johnston  
    • Michael Johnston, owner of Morse Telecommunications, publisher of Slackware Professional, and Bob Young, publisher of New York UNIX, owner of ACC Bookstore.
    • Linux is the freely distributable UNIX clone available by FTP from many sites on the Internet.  It is a remarkably complete and stable OS for Intel-based PC's that is a direct result of the existence of the Internet, which allowed for the cooperative development team of volunteers to communicate in real-time during their development of their respective parts of the project.  Linux continues to enjoy rapid development and is already a viable and popular alternative to commercial UNIX OS's.  It is being installed in basements and at commercial, academic, and governmental organizations around the world.  Michael Johnston, developer of the new Slackware Professional Linux package (in partnership with Patrick Volkerding, author of the Slackware distribution of Linux on the net), will speak on the differences between the different Linux distributions available "for free" by FTP on the Internet, and in particular the changes in Slackware (the most popular Linux distribution on the net) between versions 1.2 and the new 2.0.
    • Timestamped Version
    • AI Transcript

  12. (1994)  Leeches, Lamers, and Losers  -
    • With so many new people being drawn to the net every day, the criminal element is bound to become more visible.  This means users who destroy files, wipe entire systems, harrass users, and cause intentional pandemonium.  Perhaps the worst part of this is that the media considers such deliberate malice to be another part of hacking.  How do hackers deal with such users and the misperceptions of the hacker world that are created?  Is it proper for hackers to go to the authorities on such occasions or will that ultimately backfire?  You'll hear stories, experiences, suggestions, arguments, etc. from experts and non-experts alike.

  13. (1994)  The Art of Boxing  - BillSF, Kevin Crow, and Mark Abene (Phiber Optik)  
    • Contrary to popular belief, boxing is not dead.  As you will see, there are so many possibilities.  We will have some top phone phreaks on hand to show you what works, what doesn't, what used to work, what never did, and what probably might.  American boxing is only one small part of the entire global picture.  In this panel, we guarantee all questions will have answers.  Also included: An overview of current inband systems like R1, R2, and C5.  The pains of ANI and the ease with which it can be spoofed.  Phiber calls in from prison.
    • AI Transcript

  14. (1994)  Hacker Authors Panel  -   
  15. (1994)  The History of TAP Magazine  - Cheshire Catalyst  
    • From the early seventies to 1983, the major source for technically "subversive" material was TAP Magazine, a publication still eagerly traded by hackers and phone phreaks today.  Originally started by the Yippies and Abbie Hoffman, TAP evolved into a cornerstone for phreaks all over the world.  The last editor of TAP, Cheshire Catalyst, will tell the story and answer your questions.  This is where it all began.
    • AI Transcript

  16. (1994)  $2600 Magazine Panel  - Evil Corley, David Ruderman, Scott Skinner, Joe630, (Ben Sherman)  
    • How did it all start?  How did it almost never happen at all?  Are our phones tapped?  What's the craziest letter we ever got?  Who are the people behind the names?  How many lawsuits have we been threatened with?  What do the covers mean?  Where is it all leading?  Get the picture?
    • AI Transcript

  17. (1994)  Legal Issues and the Clipper Chip  - Dave Banisar  
    • Dave Banisar of the newly formed Washington D.C. based Electronic Privacy Information Center (EPIC) will fill us in on the latest laws, restrictions, and risks facing us all.  There will also be updates on the $2600 Pentagon City Mall incident and tips on how to make the Freedom of Information Act work for you.  Come to this panel with any questions or comments about the ACLU, EFF, CPSR, etc.
    • AI Transcript

  18. (1994)  What is this Cryptography Stuff and Why Should I Care?  - Bob Stratton, Eric Hughes, Matt Blaze, and Bernie S.  
    • There have been quite a few articles in the national media recently about cryptography and privacy.  Bob Stratton will attempt to provide an introduction to the terms and technology, how it affects the average citizen, and insights into the public policy debate currently raging in Washington and around the world.  There will be a special emphasis on the relationship of cryptographic technology and emerging personal communications tools.
    • Also, a demonstration by Bernie S. and John Turbo of the AT&T Surety Telephone Device 3600, the world's first Clipper Chip telephone encryption unit.  Attendees will be invited to make telephone calls between two AT&T 3600's and a loudspeaker will enable all present to actually hear the encrypted audio.  An actual Clipper Chip will be given away as a door prize with the opportunity to smash it with a hammer in front of all.
    • AI Transcript

  19. (1994)  Closing Ceremonies  - Various HOPE staffers  
    • Door prizes will be awarded, we'll hear from Phiber Optik in prison, comments, questions, and answers from the audience, and a message from the President.
    • HOPE Car Keys
    • AI Transcript



Beyond HOPE




[garth1]


  1. (1997)  HIP Opening and the Beyond HOPE Press Conference  - Rop Gonggrijp, Evil Corley, Cheshire Catalyst (Robert Osband), Deth Vegtable (Luke Barrymore), Phiber Optik (Mark Abene), CyberJunkie, Zap
    • The Hacking In Progress (HIP) outdoor hacker event in Holland was taking place at the exact time as Beyond HOPE in New York City.  Through a really poor video connection, we attempted to address the overseas conference as they opened early in the morning.  As we kick off the conference, we thought it would be only right to take questions from the various members of the press who will be in attendance.  This will also be the time where we will be announcing things too shocking to be printed here.  It's a good opportunity for all of us to meet the people who will be covering the conference and to dispel all those myths and rumors that seem to follow us around the planet.
    • AI Transcript

  2. (1997)  The $2600 Panel  - Evil Corley, Pamela Finkel, David Ruderman, Bernie S. (Ed Cummings), Ben Sherman (Joe630), Dave Buchwald (Bill from RNOC), Kiratoy (Shawn West), Scott Skinner, and Phiber Optik  
    • Since this whole thing is being thrown together by $2600 and friends, we thought it would be nice to have a panel dedicated to the zine, what has happened over the years, where $2600 is going, and what could be done better.  This is your chance to ask whatever questions you've had festering over the past 13 years.
    • AI Transcript

  3. (1997)  Opening Address - Hacking for the Next Century  - Brock Meeks  
    • In this age of heightened awareness about security and hacking, where have all the good hacks gone?  Too many are claiming the title "hacker" when they are no more than snot-nosed wannabe posers.  Or worse, downright petty criminals, as was witnessed at DEFCON when people were trying to pass counterfeit bills and bad counterfeit bills at that.  Brock will talk about where hackers have come from, where they've gone, and where they should head into the new millenium.
    • AI Transcript

  4. (1997)  Tiger Teaming Panel  - Dave Buchwald, Chris Nichols, Laura Brown, Ira Winkler, and Steve Lutz  
    • What are the implications when hacking becomes legal?  Over the years, major companies have learned to rely on the expertise of the same people they once tried to prosecute.  Hear some interesting stories about what has happened in this weird marriage of two cultures.  And decide for yourself what kind of effect this will have on the future of hacking.
    • AI Transcript

  5. (1997)  Information for the Masses  - Steven Rambam (Steven Rombom)  
    • There is so much information available on all of us, but most of it is only accessible to governments and to major companies/big business.  In this session, the hackers will "level the playing field" and access data that is not restricted, but is rather... expensive.  Or just plain hidden.  There will also be a discussion on just how much info is out there, including such categorization as religion, health, sexual preference, etc.
    • AI Transcript

  6. (1997)  The L0pht  - Brian Oblivion (Brian Hassick), Weld Pond (Chris Wysopal), Kingpin (Joe Grand), Mudge (Peiter Zatko), Space Rogue (Christopher Thompson), Tan (John Tan), and Stefan (Stefan von Neumann).  
    • This, incidentally, is the entire L0pht lineup all in one place at one time!  They will be talking about recent projects and accomplishments, not the least of which will be their adventures with Windows NT and why Microsoft would like to see them shot.  Look for some new projects to be introduced and for a discussion of emerging trends and shortcomings in the technologies that are backing them.  This will be followed by a Q&A session.
    • AI Transcript

  7. (1997)  Cryptography: Opportunities, Threats, and Implementations  - Bruce Schneier  
    • From encryption to digital signatures to electronic commerce to secure voting - cryptography has become the enabling technology that allows us to take existing business and social constructs and move them to computer networks.  But a lot of cryptography is bad, and the problem with bad cryptography is that it looks just like good cryptography; most people cannot tell the difference.  Security is a chain: only as strong as the weakest link.  In this talk Bruce Schneier will take a look at the future of cryptography: the needs, the threats, the limits of technology, and the promise of the future.
    • AI Transcript

  8. (1997)  Off The Hook Live Broadcast  - Evil Corley, Phiber Optik, and more!  
    • A special two hour live broadcast from the conference to the entire tri-state area.  Off The Hook airs weekly on WBAI 99.5 FM and has gotten a very diverse audience over the years.  This show will obviously be different than most since there aren't usually hundreds of people in the studio like there will be here.  There will be all kinds of special guests and surprises, most of which we probably won't even be expecting.  We hope to link this show to the HIP conference and have it available live over the mbone and real audio to make this the largest hacker broadcast ever.
    • A special edition of Off The Hook broadcast live from the Beyond HOPE conference at the Puck Building in New York City.  Guests include Major Hacking, CyberJunkie, Bernie S., Deth Vegtable (Luke Barrymore), Mike Roadancer, Steve Rambam, Paul from name.space, as well as a special media panel (Paper Tiger, Cyberwire Dispatch, Netly News, Japanese TV, Internet Underground).  Listen for the ring voltage complete with Caller ID data every time phone calls are taken.
    • AI Transcript

  9. (1997)  Pirate Radio  - "Steal This Radio" Staff, Lazlow Jones of the Techno-File Radio Network
    • What does pirate radio have to do with hacking?  Are you SERIOUS?!  Come on, don't be stupid.  First off, it's wrong to call micro-broadcasters pirates.  If anyone's a pirate, it's those megacorporations who take over the airwaves and dictate what it is that we watch and what kind of music we listen to.  But it's our own fault, for standing by and watching it happen.  Tonight you can begin to change.  Meet the people from Steal This Radio, low-power operation eminating from somewhere in the neighborhood.  This station has no censorship, lots of interesting and diverse programs, and a growing audience.  And there are more of these stations popping up on the dial all over the country.  Learn how it's done and hear firsthand how commercial broadcasting operates.

  10. (1997)  Corporate Espionage, or Where Hackers and Criminals Collide  - Ira Winkler  
    • A talk by (((Ira Winkler))) on how and where the hacker and criminal communities intersect.  This presentation will also address what basic skills a "real hacker" would have.  Highlighting this topic will be an "Are You Clueless?" test.
    • AI Transcript

  11. (1997)  GSM Phones and the Future  - Phiber Optik, and t0m from England  
    • One of the newest hacker toys is the GSM phone, which has been around in Europe for quite some time and has just being introduced in this country fairly recently with companies like Omnipoint and Sprint Spectrum.  We'll show the capabilities and potential weaknesses of these phones and compare the different systems that exist throughout the world.  Learn about the future of telecommunications from the people who will help to shape it.
    • AI Transcript

  12. (1997)  MetroCard  - Red Balaclava (Jeopardy Jim [Jim Vichench])  
    • The mystery transit employee who appeared at the original Hackers On Planet Earth conference in 1994 returns (via ISDN) to talk about the easily hackable but ingeniously self-correcting payment method of New York City's subways and buses.  We will also discuss the subtle - and possibly increasing - dangers of the Transit Authority's ability to trace your travels via MetroCard.
    • AI Transcript

  13. (1997)  Low-Bandwidth Access  - Cheshire Catalyst  
    • A discussion and demonstration on how to achieve Internet access using simple text-only computer terminals and web browsers to access information on the World Wide Web.  While you don't get all the graphics and whiz-bang, you can get basic information, download files, images and software for later perusal, and you don't need a Windows machine to do all this!  Webmasters will be given tips on making their pages more accessible to these users.
    • Notes
    • AI Transcript

  14. (1997)  Dangerous Legislation  - Shabbir Safdar  
    • There has been much movement recently involving dangerously vague legislation aimed against hackers and, not coincidentally, against privacy.  There are some really scary and little known details that may surprise the hell out of you.  Hear firsthand how the legislators' ignorance of technology and desire to control the masses could make your life a living hell.  Find out what you can do now to help shape pending laws on cryptography, privacy, free speech and even owning a computer.
    • AI Transcript

  15. (1997)  Cult of the Dead Cow and World Domination  - Deth Vegtable (Luke Barrymore), Mudge (Peiter Zatko), Nightstalker (Chris H. Tucker), Tweety Fish (Matt Force), Oxblood Ruffin (Laird Brown), Lady Carolin (Carrie Carolin), Sunspot, Count Zero (John Lester), and Theo de Raadt  
    • Cult of the Dead Cow is the oldest active group in the hacker underground (around since 1984), and they've got a little bit to say about the impact of the Internet on the world around us.  From Chinese dissidents to our own political activists, the underdogs finally have an advantage over the Goliath of Big Brother....  The times they are a changin'.  1997 is the Year of the Cow, and cDc is your only hope for absolution.
    • AI Transcript

  16. (1997)  Social Engineering Panel  - Zap, Manos Megagiannis, Evil Corley, Netweasel (Ryan M. Basile), Thee Joker (Jason), CyberJunkie, Bernz (David Bernick), and Asymmetry  
    • One of the panels we had the most fun with at the first HOPE was the social engineering seminar.  We expect to have at least as much fun this time as hackers attempt to demonstrate live just what it means to get unauthorized information out of a human being.  No matter how advanced and secure our networks and systems become, this is one form of hacking that can never die.  At least, not until there are no more people.
    • AI Transcript

  17. (1997)  The Kevin Mitnick Story  - Attorney Donald Randolph  
    • For more than two and a half years, Kevin Mitnick has been held in a prison by the U.S. government.  And during this whole time, all kinds of mistruths and fictions have been uttered by the prosecution, echoed by the media, and believed by the public.  On this panel, Mitnick's lawyer Donald Randolph will help set the record straight and provide some little known details on what has happened so far.  Find out who Kevin Mitnick is and who he isn't.
    • AI Transcript

  18. (1997)  Prisoners  - Phiber Optik, Bernie S., and Evil Corley  
    • One of the sadder aspects of the hacker world is the growing number of hacker prisoners.  Some victims of this will describe their experiences and what kinds of tricks the government plays on naive young people.  If you want to be a hacker who stays out of jail, it might be good to sit in on this one.  If you're interested in things that go on in our nation's prisons, prepare to have your eyes opened.
    • AI Transcript

  19. (1997)  The r00t Panel and Closing Ceremonies  - Hosaka, Entropy, rs, loki, and various HOPE staffers  
    • "The most beloved, the most hated, and the most respected hacking group of all time" (r00t description of themselves) will discuss their history, their evil deeds, and their many uses of silly putty.  Your one and only chance to see a real live hacking group yet to narq out themselves.  They're all a bunch of idiots, but they own you.
    • About eight hours after the HIP conference in Holland ends, it'll be our turn to pull the plugs.  This may take a while.
    • r00t Mourns the Loss of it's Founder  Michael Park (Hosaka) was a great hacker, friend, and a great person.
    • AI Transcript



H2K





  1. (2000)  Jello Biafra Keynote  - Jello Biafra (Eric Reed Boucher)  
    • Former lead singer of the Dead Kennedys Jello Biafra may appear to have little to do with the world of hackers.  But all one has to do is look at the many injustices we've faced over the years and the ominous overtones of what lies ahead - more laws, more crackdowns, more global controls with little or no oversight, and plenty more prisons.  There is no better spokesperson for the ongoing fight of the individual vs. the system than Jello.  What we in the hacker world are going through extends far beyond the world of computers - the issues of free speech that we're engaged in will have an effect on people everywhere for a very long time to come.  By the same token, we must remain aware of what's going on in the rest of the world or we won't see what's coming.  We guarantee - Jello will wake you up.  This is also the first time ever that a presidential candidate has addressed a hacker convention.
    • AI Transcript

  2. (2000)  The Hacker's Code  - Greg Newby  
    • This session will ask audience members to work together on a "Hacker's Code."  Is it possible to have a shared code of ethics?  Is it desirable?  Will this help distinguish hackers from script kiddies from criminals?  We will look at some possible examples, including the Hacker Manifesto, Hippocratic Oath, The Three Laws of Robotics, and others.
    • Hacker's Code
    • AI Transcript

  3. (2000)  DeCSS and the DMCA - Hackers vs. Corporate America  - Evil Corley, Jon Johansen, and Macki  
    • There has never been a case like this in the history of the hacker world.  For the first time, thanks to the Digital Millennium Copyright Act, it's actually illegal to figure things out and tell people how technology works - if the powers that be decide to keep this knowledge secret.  Since hackers throughout the world continue to decrypt, reverse engineer, figure out things, and spread whatever it is they discover to whoever is willing to listen, there is a battle brewing like none we've ever seen.  $2600 is only the first of what will likely be many defendants as the corporate/governmental fist continues ever more desperately to try to control the dissemination of information.  A look at what DeCSS is, what it's not, and how the DMCA is going to effect each and every one of us.
    • AI Transcript

  4. (2000)  Hackers of Planet Earth  - CyberJunkie, Rop Gonggrijp, and Andy Müeller-Maguhn  
    • You thought hacking was an American thing?  Think again.  There are hackers in every nook and cranny of the globe, from Bosnia to Burundi, and a lot of them are coming to H2K to share information, technique, and adventures.  This "meeting of the minds" is what the authorities fear the most.  Come join the conspiracy and make friends around the globe.
    • AI Transcript

  5. (2000)  Hacktivism - Terrorism or a New Hope?  - Reid Fleming, Oxblood Ruffin (Laird Brown), and ShapeShifter (Terrence McGuckin)  
    • We've all heard the phrase but what does it mean?  Is there such a thing as activism on the net and, if so, how does it work?  Learn just how much organization there is - and how much disorganization.  Panelists include Deth Veggie and Oxblood Ruffin from Cult of the Dead Cow, WTO demonstrator and activist Shapeshifter, and Bronc Buster, who has a nation of more than a billion people calling for his head because of some Chinese web sites he... modified.
    • AI Transcript

  6. (2000)  Hardware and Electronics Q&A Panel  - Javaman (Adam O'Donnell), Kingpin (Joe Grand), and Brian Oblivion (Brian Hassick)  
    • Do you have questions about basic electronics, embedded systems, secure hardware design, smart cards, hardware tokens, or wireless and radio technologies?  Having a problem reverse engineering your latest flea market find?  Are you sick and tired of hearing about software-only related security problems?  Not to worry!  Stop by the Hardware and Electronics Q&A Panel to explore a different form of hacking and interface directly with fellow electronics enthusiasts.  The panel will be an open discussion and will attempt to field and answer any related questions.  Three hardware hackers, Kingpin, Brian Oblivion, and Javaman, will be on hand.  Special guests may appear.
    • AI Transcript

  7. (2000)  High School Horror Tales  - Greg Newby and Various Teenaged Boys  
    • We've all read the letters from high school kids who have their copies of $2600 seized by the principal or who get suspended or even expelled for using an unauthorized command on one of the classroom computers.  Unfortunately, this seems to be the rule, not the exception.  Hear from high school kids from around the world who have suffered at the hands of the technologically inept and be shocked at some of the incredible accusations that have been hurled at them.
    • AI Transcript

  8. (2000)  Information on the Masses  - Steve Rambam  
    • How much information is out there on every one of us?  Who is able to access it?  How much can money really buy?  And just how much digging do you really have to do in order to find out the real secrets?  An update to the Beyond Hope discussion by world renowned private eye Steve Rambam that will shock, enrage, frighten, and intrigue you.
    • AI Transcript

  9. (2000)  The Jon Johansen Story  - Jon Johansen and Per Johansen  
    • On January 24, 2000, 16-year-old Jon Johansen and his father were both arrested by Norwegian authorities under pressure from the Motion Picture Association of America and the major film studios it represents.  The authorities seized his computer, some disks, and a mobile phone.  Jon, a member of Masters of Reverse Engineering, was believed to have been responsible for reverse engineering CSS (although this has never been definitively proven) and thus igniting the current controversy that has resulted in $2600 being sued in federal court for publishing the program on its web site.  Hear from both Jon Johansen and his father as they tell the story of the raid and arrest which could result in three years in prison.
    • AI Transcript

  10. (2000)  Has Anyone Learned ANYTHING?  - Rick Forno  
    • While a select few may have learned how to cope with the issues inherent in the Information Age, the majority have not.  A look at current security trends that explores exactly how far corporate America and the government have come in accepting/dealing with computer and information security.  Are we any better off now?  Have major incidents been an eye-opener to anyone?  Are current laws and processes effective?  Sadly, the report card is NOT GOOD.
    • AI Transcript

  11. (2000)  The Legal Panel  - Martin Garbus, Evil Corley, and Robin Gross  
    • What is illegal these days?  What isn't?  Just how many of these crazy laws are being passed that make a great amount of what we do illegal and punishable by more prison time than many violent offenders?  Just how bad is this going to get?  Find out what country you should be trying to escape to and what new laws are "coming down the pike" with our panel of legal experts and pundits.  This is not a panel for the squeamish.
    • AI Transcript

  12. (2000)  Lockpicking  - Barry Wels and Hans "Unicorn" van de Looy  
    • Barry "The Key" is one of Europe's leading experts on locks.  In his first presentation in the United States, he will talk about lockpick "sportgroups" that are very popular in Europe.  He will also give a demonstration for basic and advanced lockpickers.  If his suitcase is not too heavy he will bring some exotic European locks to show.
    • AI Transcript

  13. (2000)  Low-Bandwidth Access to the Internet  - Cheshire Catalyst, and The Voxy Lady  
    • A continuation of Cheshire Catalyst's Beyond HOPE discussion that will disparage flashy graphics and shockwaved sites in favor of informative text based information content that gives the user the INFORMATION they are looking for, not just glitz.
    • Notes
    • AI Transcript

  14. (2000)  Low-Power FM  - Bernie S., Pete Tridish, and Andrew Yoder  
    • Have you ever wanted to set up your own radio station?  For the first time in 20 years, it's possible to apply to the FCC and be granted a low-power community radio station license.  But before you can reach that euphoric goal of "radio by the people, for the people," there are lots of pitfalls and hurdles to cross, not to mention possible legislative problems with the whole process.  This informative discussion will go into detail about the history of the LPFM scene along with a discussion about current legislation, loopholes, and possible impacts of Congressional rulings.
    • AI Transcript

  15. (2000)  Hackers and the Media  - Robert Lemos, Doug Mohney, Viktorie Navratilova, and Deborah Radcliff  
    • Hear straight from the mouths of journalists why hackers seem to always get such bad media exposure.  These guys may not be the enemy (then again they might be - you decide) but they will offer some valuable insight into how the media works and how we can make it work to our advantage.  So far, MSNBC, ComputerWorld, and Boardwatch are represented.
    • AI Transcript

  16. (2000)  Ethics in Military and Civilian Software Development  - Sam Nitzberg, Winn Schwartau, and Robert Steele  
    • The quality with which systems are developed for either civilian or military purposes has systemic, infrastructure-wide consequences.  What are the ethical considerations present in developing military and civilian software?
    • AI Transcript

  17. (2000)  MTV - How Did It Happen?  - Izaac Falken, Tommee Pickles, and Weld Pond (Chris Wysopal)  
  18. (2000)  Cracking the Hacker Myth: A Study by the Laurentian University Hacker Research Team  - John Dodge, Bernie S., and Bernadette Schell  
    • In the past, many misunderstood groups in society have reaped the rewards of public backlash due to misinformation propagated by members of the media and authorities.  Despite what society has learned from these past cases, history has repeated itself yet again.  For at least the last decade, hacker myths have been concocted and propagated by acclaimed experts in the media and authorities in society.  What are the undercurrents that are driving this behavior?  The Laurentian University Hacker Research Team has been undertaking an independent study to create a balanced view of hackers.  They believe that hackerdom is misunderstood and grossly misrepresented to the public.  From their study, science may be able to dispel some of these myths and provide the public and organizations with a balanced view regarding hackers in society.
    • The No-So-Scientific Process
    • AI Transcript

  19. (2000)  Napster: A New Beginning or Beginning of the End?  - Jello Biafra, Glen Otis Brown, James Hanna, Keith Hopkin, Lazlow Jones, and Siva Vaidhyanathan  
    • We've read the papers and seen the hysteria.  Many of us have also been affected by the clogged bandwidth.  So what will programs like Napster wind up doing to the Net, the music industry, artists, and the consumer culture?  Hear from Professor Siva Vaidhyanathan of New York University, radio personality Lazlow, Jello Biafra, and people in the music business who are feeling the effects of Napster and the Net.
    • AI Transcript

  20. (2000)  The Old Timer Panel  - Cheshire Catalyst and Captain Crunch  
    • Hard as it may be to believe, there are hackers who have been active for twice as long as many of the H2K attendees have been alive!  Quite a bit has changed since the old days - the technology, the laws, the amount of interest (just look around you!) and there are some things that haven't changed at all.  Hear some incredible stories from the past and learn a bit about the origins of the hacker culture.
    • AI Transcript

  21. (2000)  The King's Mob Open-Source Mediamaking Panel  - Matt Pizzolo  
    • NYC's do-it-yourself new media and movie studio, King's Mob Multimedia, will present a panel discussion on open-source mediamaking and how the DiY ethic can shatter major corporations' grasp on independent production and distribution.  From DeCSS to the WTO protests, the world is learning that technological convergence means more than a TV that is also a microwave: technology gives us the means to converge people and cultures and to set information free.  It's all about empowering voices that wouldn't otherwise be heard.  The King's Mob's first release, THREAT, is a DiY movie about kids coming of age in a world of violence and intolerance, recognizing too late that the establishment pits us against one another across lines of race, gender, and privilege.  The movie was a four year collaboration between over 200 kids from numerous cultures and lifestyles across five countries.  It has since toured skateparks, hip hop clubs, and punk shops from LA to Berlin.
    • AI Transcript

  22. (2000)  Pirate Radio 101  - DJ Anne Animus, Mr. E, DJ Ken-Zo, and Professor Klystron  
    • A demonstration and presentation of a portable microradio station providing live, wireless audio transmissions throughout buildings and neighborhoods and around the world via the Internet.  Although the revolution will not be televised, this panel discussion will inspire hackers to get involved in our fight against short-sighted, out-of-touch governmental regulatory agencies and the large, powerful corporate puppeteers who control them.
    • Low-Power FM Transmitter Circuits
    • AI Transcript

  23. (2000)  Internet Radio  - FearFree, Juintz (Mike McTeague), and Porkchop (Michael Kaegler)  
    • While it's true that radio space on the dial is controlled by fewer and fewer people, broadcasting on the net is something that almost anyone can do.  Hear from someone who actually does it - how to get started, how to do it right, and how you can make a difference
    • AI Transcript

  24. (2000)  Retrocomputing  - Graphix, Mr. Ohm, Nightstalker (Chris H. Tucker), and Sam Nitzberg  
    • This panel will discuss and explore "obsolete computers" such as TRS-80s and Atari 800s.  It will be open to techno-geeks who know everything there is to know and newbies who wish to learn about these interesting systems from long ago.  People are urged to bring their old computers (for the retro network table) and a mini-network of old computers will be created.  The panel will also be a sort of swap meet for those looking for parts they cannot find in stores.
    • AI Transcript

  25. (2000)  The Robotic Graffiti Writer  - The Institute for Applied Autonomy  
    • The Institute for Applied Autonomy (IAA) is a politically motivated robotics collective which develops technologies to both counter existing military/police technologies as well as extend the autonomy of human activists.  The IAA has already completed and tested the Robotic Graffiti Writer (developed in part with funds from RTMark) as well as the propaganda distribution device, Little Brother.  Current research includes a street worthy prototype of the GraffitiWriter as well as new innovations in technologies for surveillance of police actions/movements.
    • AI Transcript

  26. (2000)  Selling Out: The Pros and Cons of Working for The Man  - Scott Blake  
    • There's lots of talk in the media about hackers who get straight jobs in the security industry.  What does it cost a hacker to get a real job?  What are the benefits?  What about those nasty intellectual property agreements?  Scott Blake runs the RAZOR security research team.  He actively recruits and manages hackers for BindView, a publically traded software company.  He's defended this to the executive management and the press.  In this talk, you'll hear it straight about what you have to give up for the paycheck, as well as what you get to keep.
    • Slides
    • AI Transcript

  27. (2000)  Social Engineering Panel  - Cheshire Catalyst, Evil Corley, Robert J. Lupo (v1ru5), and Kevin Mitnick calling in from prison  
    • Home of the first social engineering panel back in 1994, we continue the tradition this year with more tales of triumph and disaster plus some live telephone antics that should leave you in stitches or put us in cuffs.  Panelists are still being rounded up for this one - if you think you're worthy, let us know why.  Hear how we intercepted an AT&T security bulletin about this very panel and used it for some serious laughs.  Also, Kevin Mitnick joins in over the telephone with his interpretation of what social engineering is and isn't.
    • AI Transcript

  28. (2000)  Spy Stuff: Everything You Never Believed But Wanted to Ask About  - Robert Steele  
  29. (2000)  The Mock Trial - The MPAA vs. 2600  - Adam Cohen, Evil Corley, Jon Johansen, Glenn Kurtzrock, Bernie S., Shana Skaletsky, Scott Skinner, and Alexander Urbelis  
    • When we first scheduled this, our REAL trial wasn't supposed to happen until December.  Then things changed and the trial was moved to the DAY AFTER H2K!  Well, how could we resist?  What better way to go into court Monday morning than to remember what the verdict of our TRUE peers had been the night before?  The fun starts Saturday with a two hour courtroom drama in which both sides will be presented as factually as can be managed.  "Lawyers" for each side will be selected as will a judge.  Email us if you think you're qualified for this - we are only considering people with some legal background and knowledge for these positions.  Expert witnesses will also be called to the stand and a jury will be selected who will render a verdict 24 hours later.  Probably a lot more exciting and jovial than the real trial which H2K attendees are encouraged to stick around for.
    • AI Transcript

  30. (2000)  Introduction to Computer Viruses  - Robert J. Lupo  
    • This talk covers how viruses work.  Bootsector, multipartite, file infectors, macro, Trojan, and fakes will all be approached in detail.  There will be detailed discussions on VBS scripts and what's in the future regarding viruses.
    • AI Transcript

  31. (2000)  Closing Ceremonies  - Cheshire Catalyst, Evil Corley, Porkchop, Bernie S., and Ben Sherman (Joe630)  
    • The final words from H2K as thanks are given, door prizes are flung, cleanup begins, and we all look towards 2002.
    • AI Transcript

  32. (2000)  Why Hacking NASA is a Stupid Idea  - Cheshire Catalyst
    • For some reason, the National Aeronautics and Space Administration is a favorite hacker target.  Hackers, like most people, are fascinated by space travel and, like most technically oriented people, would like to travel into space some day.  Hacking NASA's computers is a stupid way to try to "impress" NASA, and only brings the wrath of federal agencies down upon them.  If space is really your interest, hear some ideas on how to really go about becoming an astronaut.  Hosted by Cheshire Catalyst, a resident of "The Space Coast" of Florida.

  33. (2000)  Secrets of the DNC/RNC  -
    • For the first time, a HOPE conference is taking place just prior to the two major national political conventions.  As you can guess, the kinds of security precautions and methods of utilizing technology are subjects that are of great interest to hackers.  Learn a thing or two about how the Secret Service plans to control things in Philadelphia and Los Angeles - and how they use and misuse technology.  Yes, we've got the frequencies.

  34. (2000)  GSM and CDMA  - Jason Hillyard
    • Curious about the next generation of mobile phone technology currently being developed and deployed around the world?  These new systems promise higher capacity, megabit-per-second mobile Internet access, and a range of sophisticated services.  How does it all work?  What kind of mobile phone systems can we expect to see in the near future?  A developer from the wireless industry explains what's hype and what's really going to happen with these emerging technologies.  Learn about GSM, CDMA, 3G, GPRS and EDGE, WCDMA, cdma2000, wireless location technologies for mobile phones, and Bluetooth.
    • GSM and CDMA Slides

  35. (2000)  Counterfeiting IDs and Identity Theft  - Bootleg (Michael Beketic)
    • You may be surprised by some of the things Bootleg will tell you about how easy it is to steal someone's identity.  Learn some of the techniques used as well as how the government routinely abuses our rights from someone who has experienced it firsthand.  Also, the future of electronic crime and what will happen when genetic engineering and quantum theory become realities.  Bootleg will also explain his DMV project and how the authorities have tried to shut it down.

  36. (2000)  Hacking Consciousness: Back Cover Text  - Chris McKinstry
    • What would be the "ultimate hack?"  Breaking into the computers of the Pentagon?  The CIA?  The NSA?  How about hacking into the human mind and reverse engineering consciousness itself!
    • In his new book, Chris McKinstry, a lifelong computer hacker, explores the origin and purpose of human consciousness from a hacker's reverse engineering perspective.  Drawing on a wide range of disciplines from computer science and neurobiology to evolutionary psychology and statistics, McKinstry makes the case that consciousness and meaning evolved to help us survive in a socially complex world, and that the same process can be duplicated inside a computer.  He discusses both the theory behind and specific implementation details of The MindPixel Digital Mind Modeling Project, an Internet based effort to construct and validate a high-resolution digital model of the average human mind from millions of Internet users worldwide.  Through numerous hands on neural network simulations, McKinstry demonstrates how the MindPixel Model can be used as the "Ultimate Training Corpus" to train an artificial neural network into true artificial consciousness.

  37. (2000)  Internet Security Using Open-Source Software  - Justin Cheung, Don Marti
    • Some practical advice on out-of-box Linux security via access control, setting up landmines, etc.  Why the future of hacking lies with open-source.  An introduction to the world of OSS advocacy with regards to security tools and strong encryption.

  38. (2000)  Cyber Civil Disobedience  - Dan Orr
    • Discusses the roots of civil disobedience from the Boston Tea Party to Martin Luther King and how hackers are follow in these footsteps.  Beginning with the ideal of hacking as a public service to improve security on the early Internet to more contemporary examples, hackers around the world have used their skills to promote social good.  In Bosnia, East Timor, and even the United States hackers have put the best traditions of free speech to work online: to draw attention to human rights abuses, criticize oppressive laws, and fight injustice.  This presentation documents the history of hacking to encourage social change and examines the question: "If hacking has proven a non-violent and effective form of civil disobedience, is it protected by the First Amendment?"

  39. (2000)  Becoming the Media - How the Web is Changing Everything  - Macki, Space Rogue
    • People like Matt Drudge are often held up as examples of how the web has changed the balance of access to the media.  However, a much more substantial and organized independent media is beginning to take form.  This workshop will explore the concept of an open newswire, allowing independent media organizations and individuals to distribute news reports to a mass audience.  Elements of sites such as Slashdot, HNN, 2600, and indymedia.org will be discussed.  If you want to get involved in these historical developments, this is a good start.

  40. (2000)  Freedom Downtime  -
    • Two years in the making, the $2600 documentary will finally be premiered at H2K on Friday evening, July 14.  The film focuses on the hacker culture as well as the efforts to prevent a new major motion picture from defaming Kevin Mitnick during his time in prison.  There are interviews with many from the hacker community as well as a cross country adventure as the "Free Kevin" movement kicks into high gear.
    • Freedom Downtime ($30)

  41. (2000)  Security Through Gaming: The Cyberwar Game  - Winn Schwartau
    • Security is no game, that's for sure.  But by using gaming techniques, we can learn a whole lot about security and how we all, as a company and a country, might be effected.
    • The Cyberwar will put you directly in the middle of a cyber-disaster and you and your associates have to figure out what the best course of action is.  As the scenario unfolds, things just get worse and worse.  Think it's easy?  Think again.  It's fun but it's tough.  There are no right or wrong answers - just intriguing possibilities that many of us have never considered.  Winn Schwartau will be our Maestro of Cyberwar, leading us through the interactive and compelling game.
    • Everyone gets to participate.  You may get to role-play a specific person or job function in the Advisory Council.  (No acting experience required!)  Or you may be a member of a Special Interest Group which challenges the Council every way they turn.  No matter how you play, you will have fun - while, the cyberworld around us collapses.
    • Don't miss this rare opportunity to take part in Cyberwar gaming.  (No you do NOT need to be a technical maven to participate; this is not a bits and bytes session.)  There are no slides handed out for this session because that would give everything away!  Be surprised.

  42. (2000)  How I Got My Own Area Code  - Cheshire Catalyst
    • Cheshire Catalyst has pulled off what has to be considered "The Ultimate Hack."  He got his own area code!  Cheshire will explain the process which all started with an upcoming area code split all the way to the first day of service for the new area code in Florida that covers the Countdown Capital of the World - 321.  See exciting footage of Governor Jeb Bush placing the first official call into area code 321.
    • How I Got My Own Area Code
    • Phone Phreaking, DMCA and Hacking  Full-length interview with Cheshire Catalyst.  This interview was part of my footage used for my thesis film New York City Hackers in Visual Anthropology.  Cheshire talks about phone phreaking history, the DMCA, and hacking.  Recorded during H2K in July 2000.
    • Originator of the 321 Area Code Ozzie Osband Dies

  43. (2000)  Ethics in the Hacker/Phreaker Community  - The Prophet
    • Join us for a panel on hacking and phreaking ethics.  Are hacking and phreaking skills a lost art?  When is it fair to use your skills, and in what ways?  Are hacking and phreaking outdated, now that computers are accessible to nearly everyone, and long distance phone service is inexpensive?  What do "white hat" and "black hat" mean, anyway?  Is it worth continuing to hack or phreak, even if it means a risk of prison?  We'll explore these questions and others.

  44. (2000)  Cult of the Dead Cow Extravaganza  -
    • The hacker scene's favorite media whores bring you: A PRESENTATION GUARANTEED TO GENERATE T-SHIRT SALES
    • You will:
      • SCRAMBLE to find a seat during the preceding session!
      • SNIFF as your pants become involuntarily clogged with feces in the heartstopping preshow minutes!
      • SHUDDER to the fiery propaganda spouted by Grandmaster Ratt!
      • SWOON when the Deth Vegetable breaks Sabrina Johnson's world gangbang record!
      • TASTE AND TOUCH your own damn self.  We don't want you near us, fool.
    • The curious will be amused, the devout rewarded, and the f*ckable ogled.
    • As an added bonus, we promise that everyone who attends the cDc presentation and coughs up $25 will receive an official cDc t-shirt.  While supplies last.  Purchase necessary.  Limited time offer.  See Veggie for details.
    • By the way, don't you go expecting another software release this year.  We asked Santa and y'all are on the wrong list.  Besides, the stuff currently under development is gonna take a while.  And it's strictly secret, so don't ask.  In fact, forget we even mentioned it.

  45. (2000)  Shortwave Radio - Precursor to the Net  - Craig Harkins, Andrew Yoder
    • Nearly a century before the Internet and before any of us were born, shortwave radio was the "information superhighway."  Although plenty of interesting communications have moved over to the Internet, shortwave radio is still the medium for literally millions (if not billions) of people.  On shortwave radio, you can hear hundreds of different broadcast stations from around the globe (everything from huge government propaganda machines to tiny, unauthorized broadcasters), "spy numbers" stations, military communications, ship-to-shore radiotelephone calls, drug runners, press services, and clandestine stations operated by revolutionary groups who want to take over a particular country.  Learn how to find the interesting stuff.

  46. (2000)  Nootropics  - Akida, Alex Pere
    • "Nootropics" are chemicals that enhance one's abilities such as memory retention and thought creation.  A discussion by Akida and Alex Perez on how they work, side effects, the legalities of such drugs, and where to obtain them.  Topics will also include cybernetic spirituality.  What does this new age of technology mean for us as spiritual beings?  Will the Internet lead to global consciousness or will it end up binding us in spiritual chains?  An exploration of different theories.  Samples allowable by law will be given out.

  47. (2000)  Bypassing Modern IDS Products  - Ron Gula
    • A review of network, host-based, and honeypot IDS technologies.  Techniques will be discussed which attempt to confuse IDS administrators and avoid detection or illicit response.  A review of anti-IDS detection techniques (SNI's packet fragmentation, RFP's whisker, loadable kernel mods, etc.) will also be covered.

  48. (2000)  The Internet - The View From Overseas  - Cheshire Catalyst
    • Five or six people will be selected from H2K registrants coming from overseas.  The discussion will address the following:
      1. How "American centric" does the web appear from your country?
      2. Whose "domain conventions" does your country follow?
      3. Are there things you do in your country you think would be a good idea elsewhere?
      4. How slowly do JavaScript and Shockwave load across oceans?
      5. How well does BabelFish and other software translate web pages?

  49. (2000)  Being a Good Samaritan Online  - Jonathan Wignall
    • The Data and Network Security Council, a U.K. not-for-profit campaign group, has been calling for improved online security/privacy protection and has conducted a campaign to privately notify hundreds of sites over weaknesses in key systems (both governmental and ecommerce), along with publicly outing selected sites to the media.  Using examples from the last year, Jonathan Wignall will outline some of the responses the council has received, and highlight the differing views of security held in the commercial, governmental and military sectors.  A guide on how you can safely warn sites, with obvious security holes, is included.

  50. (2000)  Telephone Systems of the World  - BillSF
    • A discussion of telephone systems from the earliest rotary dial to the modern digital systems.  The many differences between Numbering Zone One and the rest of the world.  Some of the serious mistakes made in the development of the modern network and likely future problems.  Security of networks, scams, politics, and extreme disparities in quality of service and rates charged.  Old and modern switching, signaling, and transmission technology.  A live demonstration and explanation of the sounds of certain switches and how to identify them.  With luck, we'll find some of the earliest equipment still in service and allow the audience to hear if technically possible.  An attempt is being made to find recordings and pictures of old systems though these are extremely rare.  We welcome any contributions of pictures and/or recordings.

  51. (2000)  Parents: Are They Your Enemies?  -
    • A panel of parents in the community discussing how they try to give guidance and set examples for the younger hackers.  A look at what it's like from another perspective - did you ever wonder what it would be like to have a hacker as a kid?  Didn't think so.  Learn some of the trials and tribulations parents go through when their offspring wind up in the hacker elite and on the FBI's Most Wanted list.  [Get your parent onto this panel and get free admission!]

  52. (2000)  The Web is a Harsh Mistress  - Bryan Maloney
    • Nations that exist in meatspace do so by the virtue of one thing: physical force.  Nothing else keeps a nation's physical borders secure (and its populace obedient).  On the net, however, the stakes are different.  What keeps systems secure?  Intelligence, ultimately.  Good security systems.  Rebellious members are eliminated as fast as their permissions can be changed.  For once the pen (or the keyboard) is truly mightier than the sword.  There is a "wild west" air about the Internet, where people do as they please with little fear of swift and merciless reprisal by the de jure rulers.  It brings danger, but also an unprecedented freedom.  But like the west of old, such freedom will become history without a clear, rational, sane "bill of rights."  This talk will consider such a bill; its origins and applications in meatspace, common concerns, issues, and pitfalls, as well as how it can lead us to a true freedom on the Internet - and quite possibly, a "free luna" here on Earth.

  53. (2000)  Number System Conversion  - Don Scott
    • An in-depth discussion of the binary, hexadecimal, octal, and decimal number systems and the use of easy-to-remember techniques to convert from one to another.  Also, the basics of binary, octal and hexadecimal math.



H2K2





  1. (2002)  Abuse of Authority  - Bernie S. (Ed Cummings) and ShapeShifter (Terrence McGuckin)  
    • Over the years, there have been many stories in the hacker world of law enforcement personnel who have abused their authority.  Two of the more dramatic cases in recent memory both come out of Philadelphia.  Many of us are already familiar with the horror story of Bernie S. who toured five dangerous prisons for over a year - not because of what he was charged with - but because the United States Secret Service was upset about his collection of information about them.  Then there is the case of ShapeShifter, $2600 layout artist, who was arrested at the Republican National Convention in 2000 (shortly after leading a panel on the RNC at H2K) and held on half a million dollars bail as if he were a terrorist mastermind - all because he had been targeted for speaking out in public.  Hear the games the authorities play and how public education really can make a difference in putting an end to such abuse.
    • AI Transcript

  2. (2002)  Access Control Devices  - Mike Glasser  
    • There are all kinds of access control devices that we come in contact with every day.  They include such things as magnet readers, proximity card readers, fingerprint readers, camera systems, biometrics, and basic standard operating procedures for a business.  This talk will be a comprehensive guide to what's out there.
    • AI Transcript

  3. (2002)  The Argument Against Security Through Obscurity for the Non-Digital World  - Greg Newby  
    • In the world of networked computers, security through obscurity is generally ineffective.  Hiding algorithms, protecting source code, and keeping procedures secret might be effective initially, but eventually the cloak of secrecy is penetrated.  This talk will examine how security through obscurity is relied upon in the non-computerized world.  When can security through obscurity work?  What risk analysis should we use to examine the role of obscurity in the non-computerized world?  The talk will present and examine the hypothesis that an "open-source" mentality should be applied to security procedures for public places.  This is a logical extension of the lesson in cryptanalysis - that no cryptographic method can be considered trustworthy until it has undergone a rigorous examination by qualified persons.  Similarly, can we trust security procedures in the physical world designed, ostensibly, to protect the public if these procedures never undergo public scrutiny?
    • Slides
    • AI Transcript

  4. (2002)  Black Hat Bloc or How I Stopped Worrying About Corporations and Learned to Love the Hacker Class War  - Gweeds (Guido Sanchez)  
    • Hackers must deal with governments and ultimately the corporations that wield most of the decision making power within them.  Looking over the past few decades of hacker interaction with corporations, we notice some interesting trends in the two worlds that indicate strong influences of the corporate and hacker worlds on the other's ethics and culture, often only hinted at to the rest of the world via biased corporate PR machines in the form of broadcast and publishing media.  Hacker posts to Bugtraq become resumes, hacker tech like BBSes and IRC become the technical implementations of every Internet startup's business plan, hackers testify in front of Congress to warn them of impending doom directly resulting in increased federal cybercrime funding, while piracy is accepted by governments and media (but not the public) as theft.  Has hacking become the fast venture capitalist track to shiny gadgets that go fast and make noise, a la Slashdot?  Should we ignore intellectual property legislation and treaties that are passed solely to make rich people richer?  This talk takes a look at where hacker/corporate/government relationships have been, where they are now, and where they could be going - hopefully shedding some light on everyone's motivations along the way.
    • AI Transcript

  5. (2002)  Bullies on the Net - The Ford and Nissan Cases  - Evil Corley, Eric Grimm, and Uzi Nissan  
    • We could fill the entire weekend with stories like these and we have no doubt there will be many more such tales in the years to come.  With the help of agencies, corporations, treaties, and laws with acronyms like ICANN, WIPO, WTO, and the DMCA, the individual very often finds himself at the mercy of corporate giants with virtually unlimited funding - and seemingly unlimited power.  Throughout it all however, there remains hope.  Hear the story of Uzi Nissan, who is being sued by the Nissan Motor Company for daring to use his own name on the Internet.  We'll also talk about how the Ford Motor Company sued $2600 - and lost.
    • AI Transcript

  6. (2002)  Caller ID Spoofing  - Lucky225 (Jered Morgan) and Tray Smee  
    • A demonstration of how Caller ID works as well as methods that can be used to emulate and display spoofed Caller ID messages on Caller ID and Caller ID with Call Waiting boxes using a Bell 202 modem.  Details on the technical aspects such as Caller ID protocol for both regular and Call Waiting Caller ID.  If all goes well, you may actually see a live demonstration of spoofed Caller ID.
    • Notes
    • ANI and Caller ID Spoofing  - Very detailed article on the commons methods to spoof the Calling Party Number (CPN) parameter and even ANI, by Lucky225
    • AI Transcript

  7. (2002)  "The Conscience of a Hacker"  - The Mentor (Loyd Blankenship)  
    • Probably the most famous single essay about what it's like to be a hacker is The Conscience of a Hacker by The Mentor, written in 1986.  It's been quoted all over the place, including the movie Hackers.  It remains one of the most inspirational pieces written about the hacker community and it's survived well over time.  This year, we're pleased to have The Mentor himself give a reading of it and offer additional insight.
    • Video Excerpt
    • AI Transcript

  8. (2002)  Conspiracies  - Gonzo DeMann (Michael J. Ferris), Leo, and Rev. Sergey  
    • Technology can be a wonderful thing, but it can be quite harmful as well.  Unenlightened corporate interest as well as government interest can make for some savage bedfellows.  This panel will deal with technology, its good uses and some of its evil ones.
    • AI Transcript

  9. (2002)  Crypto for the Masses  - Matt Blaze, Greg Newby, and Anatole Shaw  
    • This panel will approach cryptography from the perspective of enabling a "digital world" where key social schemes are preserved - personal identity, anonymity, and the right to privacy.  We'll talk about the basic inner workings of cryptosystems, and discuss how they can be applied now to create and enforce cyber rights.  We'll also discuss the hurdles faced by crypto and its adopters, along with the public at large.  And we'll learn just how crypto is being threatened and abused by certain global goons.
    • AI Transcript

  10. (2002)  Cult of the Dead Cow Extravaganza  -
    • This year, the megamerican computer hackers of patriotism, Cult of the Dead Cow, honor our country with "Hooray for America!" -- an all-star revue including the Anheuser-Busch Clydesdales, NASCAR champion Dingus McProstate, and the Dallas Cowboy Cheerleaders.  Reid Fleming will give a thorough and thoroughly educational description of the history and symbology of the Great Seal (which you can find on the back side of a $1 bill).  Grandmaster Ratte himself will lead the audience in a sustained chant of "U.S.A.!  U.S.A.!  U.S.A.!"  Oh, and maybe there will be some new software too

  11. (2002)  Databases and Privacy  - Steve Rambam (Steve Rombom)  
    • Once again, world renowned private eye Steve Rambam will enlighten and frighten attendees with the latest updates on the personal information that is out there about each and every one of us.  Find out which databases contain the most invasive information and who has access to them, as well as what you can do to protect your privacy.  There will also be a discussion on truth and accountability on the net as well as live demonstrations.
    • AI Transcript

  12. (2002)  A Day in the Life of a Directory Assistance Operator  - Cheshire Catalyst  
    • Odds are most of us take things about the phone companies for granted.  But there is a whole world that we don't see which is always operating.  Hear how the system really works from The Cheshire Catalyst.
    • Slides & Notes
    • AI Transcript

  13. (2002)  The DeCSS Story  - Evil Corley, Robin Gross, and Ed Hernstadt  
    • At our last conference, we were preparing to go on trial for daring to have the code to DeCSS on our web site.  Quite a lot has happened since then.  The public perception of entities like the MPAA and the RIAA has gone down the toilet as their true motives became apparent.  We were the first in what will be a long line of courtroom battles to defend freedom of speech, fair use, and open-source technology.  While we lost the case and the subsequent appeal, we still somehow feel victorious.  Find out why.
    • AI Transcript

  14. (2002)  Digital Demonstrations: Criminal DDoS Attack or Cyber Sit-in?  - Maximillian Dornseif  
    • Being able to carry political opinions to the public by showing them on the street is a basic part of democratic rights.  Nowadays, a steadily increasing part of our life takes place in cyberspace.  Things which aren't happening in cyberspace will therefore get less and less public attention.  How can protest be taken into the virtual realm?  What strategies for "online demonstrations" have we seen so far?  How about the ethical and legal dimensions?  Who gets hurt?  Host Maximillian Dornseif will present a new approach for conducting online demonstrations without adversely affecting other users on the net.
    • AI Transcript

  15. (2002)  DMCA Legal Update  - Mike Godwin, Eric Grimm, and Robin Gross  
    • Since we last met, the Digital Millennium Copyright Act has claimed more victims and been at the forefront of all kinds of legal action.  We even had the first instance of a programmer being thrown into prison because of a program he wrote while in his native Russia!  Hear the latest on the Dmitry Sklyarov case and others that the DMCA is responsible for as well as what is being done to put an end to it.
    • AI Transcript

  16. (2002)  Domain Stalking  - RenderMan (Brad Haines)  
    • Ever wanted to legally have a $900 million dollar company in your debt?  Intellectual property is a big deal to a lot of companies (witness the $2600 vs. Ford case) and it can be very easy to legally screw with it.  This presentation will be a discussion of how easy it can be to get a company in your debt by simply watching their domains and catching them when they neglect to renew.  It's a bigger problem with large companies than you think and can be exploited for many good causes.  Hear how everyone from Symantec to the Red Cross to Jello Biafra has benefited from RenderMan's watchful eyes.
    • Additional Info
    • Slides
    • AI Transcript

  17. (2002)  Educating Lawmakers - Is It Possible?  - Declan McCullagh and Matt Blaze  
    • Trying to educate Congress about technology is approximately as useful as teaching a pig to type.  It doesn't work and you get one peeved pig.  But there are sometimes ways to make a difference in law and policy circles without becoming a wholly owned tool of the Demopublican Party.  A discussion with journalist Declan McCullagh and cryptologist Matt Blaze.
    • AI Transcript

  18. (2002)  Face Scanning Systems at Airports: Ready for Prime Time?  - Richard M. Smith  
    • A talk about the technical problems of face scanning systems being used at airports to pick out terrorists.  Will these systems work like the promoters are claiming they will?  Or will they fail to catch terrorists and instead turn our airports into round-up zones for petty criminals?
    • AI Transcript

  19. (2002)  Freedom: File Not Found  - Bryan Maloney  
    • Since the explosion of the world network in the early 1990's, visionaries and pundits have been promising that "information wants to be free" and the web's free exchange of knowledge and ideas would be a liberating political and economic force throughout the world.  It's been almost ten years now: where is this newfound freedom, especially in places like China?  The Middle East?  What about right here at home?  This talk will discuss government/corporate efforts to restrict the free flow of information on the Internet and the political, ethical, and socioeconomic consequences.  Topics will include hardware in use by the People's Republic of China to monitor and censor information it deems "subversive," routing tactics in Saudi Arabia to enhance government oversight and censorship, and the constitutionality of email snooping hardware and software in use in America.  A Q&A session will follow.
    • AI Transcript

  20. (2002)  F*cking Up the Internet at ICANN: Global Control Through the Domain Name System and How to Escape  - Andy Müeller-Maguhn  
    • Did you know that the entire Internet domain structure is controlled by a mysterious group called the Internet Corporation for Assigned Names and Numbers (ICANN)?  Andy Müeller-Maguhn, longtime member and spokesman of Germany's Chaos Computer Club and currently elected from European users to be on the board of ICANN, will explain the latest developments at ICANN and how the mixture of intellectual property and governmental interests affects the freedom of the Internet.  Paul Garrin, founder of Name.Space and Free.The.Media!, will talk about his initiatives to establish rights to access to the legacy ROOT.ZONE, from the historical antitrust action against Network Solutions in 1997 through the U.S. Department of Commerce's IFWP process (the predecessor to ICANN), and Name.Space's $50,000.00 TLD application to ICANN in 2000 (ICANN kept the money and took three TLD's previously published by Name.Space).  The question is raised: Is there hope for seeking fair access to the legacy ROOT.ZONE through due process or is it time to treat ICANN as "damage" and route around it?
    • AI Transcript

  21. (2002)  Fun With 802.11b  - dragorn (Michael Kershaw), Porkchop (Michael Kaegler), and StAtIc FuSiOn  
    • Would you be surprised if you could turn on your laptop anywhere in the city and find yourself on someone else's network?  How about if you were able to connect to the Internet?  Or see someone's private data go flying by?  It's all possible and it happens all the time - all over the country.  This panel will cover 802.11 wireless ethernet networking basics, as well as detecting and monitoring wireless networks with active and passive methods.  Community free networks, custom antennas, and methods of securing wireless networks will also be covered.
    • AI Transcript

  22. (2002)  Fun With Pirate Radio and Shortwave  - Craig Harkins and Allan Weiner  
    • Too few people take the time to appreciate shortwave radio.  Even fewer have the opportunity to appreciate pirate radio.  Here's your chance to learn more about these fascinating subjects.  Allan Weiner will talk about his days operating Radio New York International, a famous pirate station from the 80's that served the New York area before it was raided by federal authorities in international waters.  (We have no idea how the feds got away with that.)  Today Weiner operates shortwave station WBCQ - along with chief engineer Timtron - which serves nearly the entire western hemisphere from studios in Maine.  Craig Harkins joins the panel to talk of his experiences operating Anteater Radio during much of the 90's from an 18-wheeler truck.  He received international acclaim from listeners while consistently evading American and Canadian radio police.
    • Low-Power FM Transmitter Circuits
    • AI Transcript

  23. (2002)  GNU Radio: Free Software Radio Collides with Hollywood's Lawyers  - Eric Blossom and Matt Ettus  
    • The GNU Radio project is building a platform for experimenting with software radios - systems where the actual waveforms received and transmitted are defined by software, not special purpose hardware.  One of their projects is building an all-software ATSC (HDTV) receiver.  An all-software free ATSC receiver would allow among other things the construction of the mother of all "personal video recorders."  Think Tivo or Replay on steroids.  The folks from the Broadcast Protection Discussion Group (BPDG) have other ideas.  They'd like to lock up the cleartext signal and make sure that only members of their club would be allowed to build receivers, modulators, and storage devices for digital TV.  A discussion of where this is all likely to head.  Panel participants include GNU Radio technical folks Eric Blossom and Matt Ettus as well as representatives from the EFF.
    • AI Transcript

  24. (2002)  Hacking for Community Radio  - Pete Tridish, Josh Marcus, Dave Arney, Roland Aguilar, and K. Clair  
    • The technical and political struggle to take back the airwaves for the community.  A panel discussion about the attempt to build Linux based free software that can stream broadcast quality audio over the Internet from a studio to a transmitter site.  In addition, there will be discussion on attempts to use wireless Ethernet to shoot broadcast quality audio across town with high-gain antennas and 2.4 GHz amplifiers.
    • AI Transcript

  25. (2002)  Hacking Nanotech  - Jim "Cipz"  
    • Nanofabrication technology is an up and coming field that will revolutionize the way humans live on a day to day basis.  Host Jim "Cipz" tells what the future projections about nanofabrication are - things like robots so small you would need an electron microscope to see them.  There will also be an examination of some amazing achievements that have been accomplished already as well as an analysis of the possible ethical problems that may arise with nanofabrication in the future.
    • AI Transcript

  26. (2002)  Hacking National Intelligence: Possibilities for a Public Intelligence Revolution  - Robert Steele  
    • Robert David Steele, author of two books on intelligence reform and sponsor of the Council on Intelligence, will provide a briefing on the state of the world, 21st Century tradeoffs that are NOT being made by our elected leaders, and how citizens can take back the power by practicing the new craft of intelligence to monitor and instruct their elected officials on key national security decisions.  Among other major aspects, this would translate into a freezing of the Pentagon budget at $250 billion a year and redirection of $150 billion a year toward global education, public health, water and energy conservation, and "soft power" options including diplomacy and information peacekeeping, a term Steele devised in the early 1990's.
    • AI Transcript

  27. (2002)  Hacking the Invisible World  - Craig Harkins, Bernie S., and Barry Wels  
  28. (2002)  Hardware Q&A Panel  - Javaman and Binary (Nick Amento)  
    • Explore a different form of hacking and interface directly with fellow electronics enthusiasts.  Javaman and friends will try to answer any questions related to hardware and electronics including but not limited to hardware tokens, radio/wireless technologies, embedded systems, smart cards, and secure hardware design.
    • AI Transcript

  29. (2002)  How to Start an IMC in Your Town  - Jello Biafra (Eric Reed Boucher)  
    • At H2K, Jello Biafra urged attendees to become the media.  Since then, many people have done just that.  One of the most powerful tools in fighting the corporate media's stranglehold on information in this country has been the Indymedia network.  Learn what's involved with becoming a part of Indymedia, the various hurdles and roadblocks you can expect to face, and how you can make a difference.
    • AI Transcript

  30. (2002)  Human Autonomous Zones: The Real Role of Hackers  - Doug Rushkoff  
    • How the role of hackers in society has changed.  They used to be a necessary counterbalance to corporate and government power.  Now, it's more like hackers are the only ones who understand the technology.  They have become a balance to the power of technology itself.  A discussion by renowned author Doug Rushkoff.
    • AI Transcript

  31. (2002)  "I Am Against Intellectual Property"  - Nelson Denoon  
    • In the words of host Nelson Denoon: "Quit f*cking apologizing for filesharing.  Intellectual property is evil, filesharing is freedom fighting, and the sooner Jack Valenti is bumming quarters for a living, the better.  The question is not how to protect artists, it is how to muster enough force to protect the right to hack."
    • AI Transcript

  32. (2002)  The Ins and Outs of Webcasting  - Lee Azzarello, Lynea Diaz-Hagan, Tarikh Korula, Lazlow Jones, and Kevin Prichard  
    • While the airwaves have been almost completely taken over by corporate interests, there is a whole world of broadcasting on the Internet just waiting for creative minds.  Find out what it takes to get an Internet station going and what kinds of creative programming are possible.  Also, learn what the recently mandated RIAA licensing fees will mean to the future of this broadcasting medium.
    • AI Transcript

  33. (2002)  Introduction to Computer Viruses  - Robert Lupo  
    • Understanding the fundamentals of how to identify, remove, and defend against hostile code.  Robert Lupo will cover how different computer viruses work - boot sector, file infector, multipartite, VBS, Java, the different OS viruses, etc.  He will also explain how to remove different computer viruses with and without anti-virus software and discuss the future of computer viruses and hostile code.
    • AI Transcript

  34. (2002)  Jello Biafra's State of the World Address  - Jello Biafra  
    • Since his keynote address at the H2K conference in 2000, Jello Biafra has witnessed further corporate consolidation and censorship of mass media.  He's also been on the front lines of the growing uprising against corporate power itself.  He may speak about that, and/or the Bush mob's cynical exploitation of the tragedy on September 11, or the corporate music biz convention on "the future of digital music" he was invited to speak at a few days before H2K2.  He's not sure yet so stay tuned.
    • AI Transcript

  35. (2002)  Aaron McGruder Keynote  - Aaron McGruder  
    • Just about everyone has at one time or another read the daily comic strip The Boondocks.  Not everyone has appreciated it.  In fact, it's generated a share of controversy among the mainstream for its "alternative" views.  In addition, McGruder has devoted space to hacker issues, most notably the DeCSS case - which was presented accurately for probably the first time in most of the papers his strip appears in.  McGruder is one of those rare individuals with access to the mainstream who actually "gets" the technical issues.  Needless to say, he has been targeted relentlessly by censors for daring to speak his mind.  Sound familiar?
    • AI Transcript

  36. (2002)  Life in a Distributed Age  - Siva Vaidhyanathan  
    • Distributed information systems of all kinds are challenging cultural and political assumptions.  The moral of the story is that whether we like it or not, it's time to take anarchy seriously.  We have spent the past 200 years thinking centralization of power and information was the greatest challenge to republican forms of government and corporatized commerce.  But now, it should be clear, decentralization and encryption have emerged as the most important dynamics of power.
    • AI Transcript

  37. (2002)  Lockpicking  - Barry Wels  
    • Barry "The Key" Wels returns from The Netherlands to provide details of some high security lock weaknesses and to demonstrate some state of the art techniques of exploiting them.  He will tell the story of a company that had the famous line "Nobody can pick this lock" on their website.  Of course, this was the ultimate motivation for the sport-lockpickers.  This panel is where you can find out if a particular lock can be picked or not.  Spare locks are always welcome, as TOOOL (The Open Organization of Lockpickers) is short of good locks.
    • AI Transcript

  38. (2002)  Low-Power FM Basics  - Pete Tridish and John Ramsey  
  39. (2002)  Magical Gadgets: The Profound Impact of Yesterday's Not-So-Trivial Electronics on Our Digital World  - Jay Hanson and Paul Zurek  
    • Rewind to an age when electronics had originality; the era when a new product was inspired by creativity.  Get the story about the evolution of IC-based devices, and see for yourself how the soul of electronics has been sold out.
    • AI Transcript

  40. (2002)  Magic Lantern and Other Evil Things  - Rudy Rucker Jr.  
    • A talk by Rudy Rucker Jr. on the BadTrans worm and the FBI's Magic Lantern software.  Both of these pieces of software are very similar and install keystroke logging software on clients' machines.  Rucker has collected a couple of gigabytes of the BadTrans data and will explain how he parsed it and created a web-based tool for people to browse the database.
    • AI Transcript

  41. (2002)  Making Money on the Internet While Still Saying "F*ck"  - Philip Kaplan (Pud)  
    • Pud of www.f*ckedcompany.com will speak about his experiences setting up and maintaining a popular Web site for corporate rumors.  How does he handle confidentiality of rumor-mongers, avoid lawsuits, provide custom software to drive the site, and make money from it?
    • AI Transcript

  42. (2002)  Negativland: Past, Present, Future  - Mark Hosler  
    • If there is any one group who personifies the concept of "fair use," that group would have to be Negativland.  The Bay Area based band has, over the years, drawn the ire of everyone from rock band U2 to American Top 40 host Casey Kasim to angry parents to confused legislators.  Founding member Mark Hosler hosts this presentation which will focus on media literacy as well as the activism, pranks, and hoaxes that Negativland has engaged in over the years.  A number of rare Negativland films will also be shown.
    • AI Transcript

  43. (2002)  The New FBI and How It Can Hurt You  - Mike Levine, Declan McCullagh, and Robert Steele  
    • On May 29, 2002 the Federal Bureau of Investigation dramatically changed its focus.  Now, instead of investigating crimes, its mission is to prevent them, meaning they have virtual carte blanche to infiltrate any law abiding organization or gathering to make sure all is right.  And, even better, their third priority of dangerous crimes to stop (next to terrorism and espionage) is "cybercrime."  We all know what a wide net that can be.  Hear the dangers firsthand from the people who follow this kind of thing.
    • AI Transcript

  44. (2002)  Open-Source Security Testing Methodology Manual  - Tyler Shields  
    • The Open-Source Security Testing Methodology Manual (OSSTMM) came about as a need for an open, free security testing methodology in response to the numerous security testing companies who claimed to have a secret, internal, and corporate confidential methodology for testing.  It was this methodology that they used to differentiate themselves from other testing companies.  The problem was that often it didn't exist and the tests turned out to be no more than commercial scanners set loose on a list of systems.  The development of the OSSTMM began as a series of logical steps to make a good test and grew into the need to make the most thorough test.  This presentation will show the origin of the OSSTMM and the logic behind it, as well as results of reverse-engineering the reports of corporate tests, commercial tools, and commercial presentations.
    • AI Transcript

  45. (2002)  The Password Probability Matrix  - Jon Erickson (Smibbs)  
    • A windowing method for brute-force password cracking using lossy compression.  Cryptologist Jon Erickson will present the specifics for a newly developed password cracking method and perform a demonstration of it.  The method is a hybrid between using computational power and storage space for an exhaustive brute-force attack utilizing a compressed matrix of probabilistic values.  He will demonstrate the ability to crack any 4 character password with a fixed salt in under 8 seconds (assuming 10,000 cracks per second), using only a 141 meg file.  A normal exhaustive brute-force on the same system would take over 2 hours, and flat text storage of the plaintext/hash pairs would normally use over a gigabyte of storage.  This translates to 99.9% keyspace reduction and 89% storage compression.
    • AI Transcript

  46. (2002)  The PATRIOT Act  - New York City People's Law Collective  
    • Members of the New York City People's Law Collective will be discussing the dangers of the PATRIOT Act and providing information on warrants, hacktivism, what is legal and what is not, and ways that hackers, activists, and normal citizens can protect themselves from The Man.
    • AI Transcript

  47. (2002)  Protection for the Masses  - Rop Gonggrijp  
    • Host Rop Gonggrijp gives updates on two projects designed to help people protect their privacy from prying eyes.  One is a localhost mail proxy for PGP that is really nice and could "save the world" as the PGP plugins stop working (soon...).  The other one is Secure Notebook, a project to create a notebook which runs Windows, yet is secure against theft.  Source for all projects will be open for review.
    • AI Transcript

  48. (2002)  Proximity Cards: How Secure Are They?  - Delchi  
    • They're used everywhere but they could be making you even more vulnerable to privacy invasion.  Delchi has been working with proximity based card systems for two years and has developed a method of casually extracting data from proximity cards in a public environment.  Riding in an elevator, subway, or just walking down the hall, a person can bump into you, say "excuse me," and walk away with the decoded information from the proximity card in your pocket.  It could then be possible to build a device that can capture and replay these snippets of information on demand or to even brute-force a proximity card system.  This talk will focus on the vulnerabilities of the systems and show a low-power working prototype.  Alternatives will be discussed, as well as other vulnerable aspects of proximity based building and computer access systems.
    • AI Transcript

  49. (2002)  Report From Ruckus  - The Ruckus Society  
    • Very recently, history was made in California as The Ruckus Society held its first-ever Tech Toolbox Action Camp.  It lasted for a week and brought together geeks and activists from around the world who shared information on how they're using the Internet and other technologies in working for change.  Part of the goal was to emerge from this and show others what they learned.  Some of the attendees of the Ruckus Camp will be here to do just that.
    • AI Transcript

  50. (2002)  Retrocomputing  - Mr. Ohm, Sam Nitzberg, Nightstalker (Chris H. Tucker), and Bernie S.  
    • This year's retrocomputing panel will focus on hardware hacking and cloning such systems as the Apple ][ and C64.  Also included will be a discussion on homebrew microcomputers and kits from the 70's as well as antique cellphone hacking.  Witness firsthand genuine pieces of history.  Attendees are encouraged to bring their really old (working) computers for the "retrocomputer neighborhood" in the network room.
    • AI Transcript

  51. (2002)  Secure Telephony: Where ARE the Secure Phones?  - Eric Blossom and Rop Gonggrijp  
    • Panel participants will take a look at the history of secure phones, what's worked and what hasn't, who the players are, and what needs to happen to make truly secure telephony a ubiquitous reality.  Panel members include former Starium CTO Eric Blossom and Rop Gonggrijp of NAH6.
    • AI Transcript

  52. (2002)  The Shape of the Internet: Influence and Consequence  - Javaman  
    • Network researchers have discovered strong power law relationships in the Internet.  These can be interpreted as a direct fingerprint of the fractal structure present on the net.  Work has only recently begun on analyzing the implications of such a structure on attack tolerance, government snooping, and the like.  In this talk, a review of these topics will be presented, along with a proposed network structure that can avoid such issues.
    • AI Transcript

  53. (2002)  Social Engineering Panel  - Bernie S., Evil Corley, Cheshire Catalyst, and Alexander J. Urbelis  
    • A tradition started at the first HOPE conference in 1994, the social engineering panel remains one of our most popular each and every time.  It would be wrong for us to tell you what we have planned because then our victims might have a fighting chance of escaping.  Suffice to say, we will find someone somewhere who will tell us something they really shouldn't have because they believed we were somebody we weren't.  This panel is always open to participants so if you feel you're worthy, just let us know during the conference and you might find yourself up on stage trying to be clever on the phone.
    • AI Transcript

  54. (2002)  Standing Up To Authority  - John Young and Deborah Natsios  
    • "How is it you folks have gotten away with not getting shut down by the powers-that-be?" is the question most frequently asked of Cryptome since its inception in 1996.  Post-9/11 H2K2 is an opportune time and place to reconsider implications of this question with Cryptome founders John Young and Deborah Natsios, New York City-based architects (of bricks and mortar), who will discuss their means and methods of sustaining activism in the face of opposition, with reference to ongoing cases.
    • AI Transcript

  55. (2002)  Steganography: Wild Rumors and Practical Applications  - Peter Wayner  
    • Is Osama bin Laden sending coded messages in the pictures of goods for sale on eBay?  Is that MP3 file carrying a secret note that tracks the listeners?  Steganography is the art and science of hiding information in digital data and it stretches the boundaries of information theory and philosophy.  An artful programmer can hide secret messages in such a way that a 1 is not always a 1 and a 0 is not always a 0.  This talk will explore some of the popular schemes for inserting messages and discuss how they're used by hackers, poets, corporate bean counters, and programmers on a deadline.
    • AI Transcript

  56. (2002)  Strategic Thought in Virtual Deterrence and Real Offense: The Computer's Role  - Wanja Eric Nae, and Sam Nitzberg  
    • Computers are pivotal components in modern society: daily life, banking, and military.  What must be considered and what risks do we all face when they are used in conflict?  These concerns are societal in nature and apply to both "minor" and "major" groups, governments, and militaries.  There will be opportunity for ample questions from the audience.  The intention is to share the overall attendee perspective.  The goal is to be thought provoking, not scare-mongering.
    • Slides
    • AI Transcript

  57. (2002)  Teaching Hacker Ethics with a Common Curriculum  - Greg Newby  
    • An introduction of a new proposed curriculum guideline for teaching information ethics to students in elementary school, high school, and college.  This curriculum is being proposed through the North Carolina chapter of Computer Professionals for Social Responsibility.  The idea is to foster creative, exploratory, effective, and intelligent use of information tools (a.k.a., the hacker ethic), rather than powerless end-user mentality.  There are many reasons to desire a common suggested curriculum for different educational levels.  We might argue that most major advances in computing were brought about by hackers.  We could point out that it's necessary to encourage creative and exploratory behavior for the next generation of computer users to do brilliant things.  For today's hackers, the goal is simply to shape tomorrow's hackers so that they will use their abilities to help create a better society.
    • Slides
    • AI Transcript

  58. (2002)  Technomanifestos: Visions of the Information Revolutionaries  - Adam Brate  
  59. (2002)  Tracking Criminals on the Internet  - Richard M. Smith  
    • How certain criminal investigations have been investigated in the past couple of years with perps being tracked by IP addresses, email, and web surfing.  Such cases include the murder of Daniel Pearl, the search for bin Laden, the Melissa virus release, the Clayton Lee Waagner escape, the anthrax attacks, and the Wakefield mass murders.
    • AI Transcript

  60. (2002)  The Ultimate Co-location Site  - Avi Freedman and Ryan Lackey  
    • Sealand was founded as a sovereign principality in 1967 in international waters, six miles off the eastern shores of Britain.  The island fortress is conveniently situated from 65 to 100 miles from the coasts of France, Belgium, Holland, and Germany.  HavenCo has been providing services since May 2000 and is fully operational, offering the world's most secure managed servers in the world's only true free market environment - the Principality of Sealand.  Avi Freedman and Ryan Lackey of HavenCo will talk about the challenges and potential of this unique working environment and what it could mean to the future of the net.
    • AI Transcript

  61. (2002)  The Vanished Art of Human Intelligence  - Mike Levine  
    • A collection of videos and analysis by WBAI talk show host and 25 year federal agent Mike Levine.  Learn about the dangers of the use of human intelligence in the hands of amateurs and imagine what is about to happen under the new anti-terrorism laws.
    • AI Transcript

  62. (2002)  Freedom Downtime Question & Answer Session  - Michael Kaegler, Gus Gustafson.
  63. (2002)  Closing Ceremonies  -
    • A final review of the events of the weekend along with all kinds of guests, giveaways, and more.  Remember, only wimps leave early.
    • AI Transcript



The Fifth HOPE





  1. (2004)  AS/400: Lifting the Veil of Obscurity  - StankDawg (David Blake)
    • The AS/400 system from IBM is a powerful system that is in widespread use.  Despite that, it is difficult to find information on it or learn about it from any school.  A general overview of its design and the architecture of the OS will be presented.  This will then be tied into fundamental computing knowledge to show where "interesting" data can be found and where possible weaknesses are in the system.
    • AI Transcript

  2. (2004)  Automotive Networks  - Nothingface
    • This presentation provides an introduction to the electronic networks present on late model automobiles.  These networks will be described loosely following the OSI model of networking.  Common uses of these networks will be presented and the privacy implications of some uses will be questioned.  The presentation will conclude with an introduction to OpenOtto, a free software and hardware project implementing the network protocols previously described.
    • AI Transcript

  3. (2004)  Bloggers at the DNC  - Brad Johnson
    • The Democratic National Convention has become a sclerotic, television-driven celebrity parade.  This year bloggers - a.k.a. hacker journalists - are being invited onto the floor to shake things up.  Can the Internet bring democracy back to the mother of all Democratic Party shindigs?  The panel will talk about what is planned - from Wi-Fi to video blogging - and how you can get involved, in Boston or remotely.
    • AI Transcript

  4. (2004)  Building Hacker Spaces  - Binary (Nick Amento), Count Zero (John Lester), Freqout, Gweeds (Guido Sanchez), Javaman (Adam J. O'Donnell), Mangala, Shardy, Rev. Al, and Dr. Nick
  5. (2004)  Building the Anti-Big Brother  - Peter Wayner
    • This will be a talk on how databases can do useful work and serve society without storing any personal information.  For the past several years, Peter has been exploring how banks, stores, and businesses everywhere can offer their customers personalized service without keeping personal data about them where it can be abused by nefarious insiders or malicious outsiders.  Building these systems requires more of a change in attitude than a change in technology because all of the solutions use standard encryption tools as a foundation.  Topics will include how to build these systems and when they can help make the world a safer, saner place.
    • AI Transcript

  6. (2004)  Bypassing Corporate Restrictions from the Inside  - barbwire
    • Working for an organization can be annoyingly restrictive.  As they feel they need to cater to the lowest common denominator, you are subjected to web content filters, outgoing port restrictions, and firewalls.  This panel attempts to provide an understanding of how these restrictions are usually implemented and how techniques such as tunneling can be your saving grace.  It will also address potential security implications and measures that should be considered whenever you compromise your own company's infrastructure.
    • AI Transcript

  7. (2004)  Cheshire's Rant Session  - Cheshire Catalyst
    • When The Cheshire Catalyst spoke about problems at his Directory Assistance job at H2K2, corrections that nobody could get done in over three years were miraculously being made within two weeks after getting back to work following the convention.  Could telephone company agents have infiltrated the convention and reported back?  What other Large Corporate Problems aren't corporate executives listening to?  Write out your rant and be sure you can deliver it in 45 seconds (isn't that what the stopwatch mode on your digital watch is for?).  When it's all over, any hyperlinks mentioned by ranting attendees will be available on the web, allowing the Agents of Normality to not only find out what you're ranting about, but have your own references to work from when they report back to their executives.
    • AI Transcript

  8. (2004)  The CryptoPhone Project  - Rop Gonggrijp and Barry Wels
    • Trying to keep government out of everyone's phone calls is a lost battle.  What little legislation we had to protect us will be removed in the next few years and ignored until then.  Storing the content of all phone calls forever is now affordable, even for smaller countries.  Strong end-to-end cryptography on a massive scale is the only answer.  But where are the phones?  CryptoPhone makes a phone based on a commercially available PDA/phone that features an open protocol and published source code.  And there's a free Windows client if you don't want to buy the phone!  The talk will outline precisely how it works, what's next, and how you can help.
    • AI Transcript

  9. (2004)  Cult of the Dead Cow Hactivism Panel - Part 1  - Eric Grimm, Sharon Hom, Dr. James Mulvenon, Oxblood Ruffin (Laird Brown), and Nart Villeneuve  
    • Cult of the Dead Cow Hactivism Panel - Part 2
    • Over 40 years ago, Marshall McLuhan declared that the Third World War would be an information war in which civilians and the military wouldn't be particularly distinguished.  That vision has become a reality.  Governments from China to Zimbabwe have strangled access to information critical of their regimes, often with the aid of American companies.  And as quickly, resistance has sprung up to challenge that repression.  Areas of opportunity are beginning to emerge as hackers, human rights activists, and the academic community begin to join forces.  This panel will explore the phenomenon of state-sponsored censorship and grassroots resistance from the political, legal, technological, and human rights perspectives.
    • AI Transcript

  10. (2004)  Digital Rights Management  - Michael Sims
    • Digital Rights Management is quickly becoming pervasive in electronic devices of all sorts.  This minimally-technical overview of DRM systems in use now and planned for the future will show you how and why your ability to make use of electronics is being reduced by corporate desires to increase profits and exercise control over their products.  The emphasis here will be on DRM systems that have gotten little publicity.  The DVD CSS system will be touched upon but most of the time will be spent describing systems for controlling television broadcasts, DRM built into CPUs and BIOS's, and other areas that haven't gotten nearly as much attention as CSS.
    • AI Transcript

  11. (2004)  Distributed Password Cracking API  - David "Bernz" Bernick
    • The low-cost of the modern PC, the proliferation of the Internet, and the speed of its underlying networks make parallel task-based computing very possible.  We've seen massive networks like SETI demonstrate this.  SETI is programmed for a simple task: Get a piece of data, process it at leisure, spit out results if any, get a new piece of data.  This has been used already to do some brute-forcing of security tasks with systems like distributed.net.  But that system is sophisticated and large and you can't make it do tasks like cracking crypt() passwords or websites or any variety of brute-forcing tasks.  This talk is about an extensible framework and API for creating distributed password crackers.  The framework is easy to use, easy to distribute, and easy to add different kinds of cracking to.  The software will be released open-source during the conference.
    • AI Transcript

  12. (2004)  Encryption Key Signing  - Seth Hardy
    • It's a surprising fact that a large number of attendees at this very conference, even those who call themselves hackers and/or security professionals, probably don't use any sort of encryption - or don't use it properly.  One reason may be because people think nobody else uses it.  So until it has a stronger presence, it won't be as widespread as it really should be.  In order to help fight this, Seth will be hosting a key signing session.  There will be a rundown of why people should be using strong crypto, how the web of trust works, and moderation to public verification of identity and key fingerprints.
    • AI Transcript

  13. (2004)  Everything You Ever Wanted to Know About Spying, 9-11, and Why We Continue to Screw Up - Part 1  - Robert Steele  
  14. (2004)  Kevin Mitnick Keynote - Part 1  - Kevin Mitnick  
  15. (2004)  Frustrating OS Fingerprinting with Morph  - Kathy Wang
    • Sun Tzu once stated "Know your enemy and know yourself, and in a hundred battles you will never be defeated."  By denying outsiders information about our systems and software, we make it more difficult to mount successful attacks.  There are a wealth of options for OS-fingerprinting today, evolving from basic TCP-flag mangling tools such as Queso, through the ICMP quirk-detection of the original Xprobe and the packet timing analysis of RING, to today's suite of multiple techniques employed by Nmap.  The ultimate advantage in the OS-detection game lies with the defender, however, as it is they who control what packets are sent in response.  Morph is a BSD-licensed remote OS detection spoofing tool.  It is portable and configurable, and will frustrate current state-of-the-art OS fingerprinting.  This presentation will discuss the current techniques used for OS fingerprinting and how to frustrate them.  There will be a live demo, and Morph v0.2 will be released with this talk.
    • Slides
    • AI Transcript

  16. (2004)  Hack Nano  - Jim "Cipz"
    • This is a continuation of Jim's presentation at H2K2 on hacking nanotechnology.  This year there will be more on developing simulation software, thinking of new ideas, and investigating current discoveries.  All of these are theory and thought driven.  There will be a demonstration of some experiments and a discussion on the realities of nano hacking and why it's an important area of exploration.
    • AI Transcript

  17. (2004)  Hacker Radio  - Sl1pm0de (Matt Smith)
    • Hacker radio is a growing phenomenon throughout the world.  Hackers are discussing the current issues faced in today's technological world over the airwaves and through the net.  There are all sorts of hacker issues being discussed via hacker radio including the DMCA or software patents in the European Union that seriously limit innovation and allow for others to have too much control over something you purchased in your home.  By having this discussion in a radio format, those outside the hacker community have the opportunity to hear it and learn.  The evolution of hacker radio from the early days of spreading information via bulletin board systems, websites, forums, and mailing lists to today's online audio streams will be explored.  There will also be a discussion of hardware and open-source software methods for setting up your own show and getting your own opinions and ideas out there for all to hear.  Current examples of hacker radio will be featured.
    • AI Transcript

  18. (2004)  Hackers and the Law  - Dr. D. Kall Loper, Annalee Newitz, and Wendy Seltzer
    • This panel will cover current legal crises around privacy, free speech, and intellectual property, with a special focus on the concerns of hackers.  Presenters will discuss the laws which protect (or don't protect) your right to anonymous free speech online, your right to reverse-engineer, and your ability to make fair use of your digital media.  They will also discuss the PATRIOT Act and the ways this sweeping set of laws changed the nature of investigation and the rules governing wiretapping online.
    • AI Transcript

  19. (2004)  Hackers in Modern Imperialist America vs. Barbarians in the Holy Roman Empire  - Christopher Davis
    • In the time the Roman Empire controlled most of western civilization, the barbarians were known as enemies to society - savages that lived in the frontiers of the empire that resisted control by the Romans.  Today, as the United States moves forward with an imperialist foreign policy, a new enemy has emerged that is resisting the system from the outskirts of the socially accepted: the hackers.
    • AI Transcript

  20. (2004)  Hacking CDMA PRLs  - The Prophet  (Babu Mengelepouti)
    • CDMA is the dominant mobile phone technology in North America and is operated by Alltel, Sprint, US Cellular, Verizon, and many other carriers.  On CDMA handsets, roaming is controlled via a configuration file called the PRL.  In this talk, you will learn how to unload PRLs from CDMA handsets, how to disassemble them, and how they can be hacked.  This talk isn't about making free phone calls or doing anything illegal, but you will learn how to determine what you're really buying when your carrier promises "nationwide service."
    • AI Transcript

  21. (2004)  Hacking More of the Invisible World  - Bernie S. (Ed Cummings) and Barry Wels
    • An update on the H2K2 panel focusing on HF, VHF, UHF, and microwave signals.  You will learn what's out there and how to intercept it.  There will also be a discussion on TSCM (Technical Surveillance Counter Measures), the art of evading electronic surveillance, and a presentation of selected intercepts and equipment demonstrations.
    • AI Transcript

  22. (2004)  Hacking National Intelligence: Power to the People  - Robert Steele
    • Do you want to live in a nation where decision makers lie, cheat, and steal?  Where national intelligence is so secret that you are not allowed to know a) the truth, b) that national intelligence (spies) are ignorant about the real world, and c) that what policy makers tell the people (e.g. about reasons to go to war in Iraq) has nothing to do with reality?  Imagine instead an America in which public intelligence supersedes secret intelligence and elitist corruption is displaced by an informed democracy in which consensus conferences at every level assure that "We the People" all serve the public interest.  That is "The OSINT Story."  Come hear the story and discuss how we are going to run the world as we achieve open spectrum, open-source software, and open-source intelligence.
    • AI Transcript

  23. (2004)  Hacking the Grid  - Greg Newby and Porkchop (Michael Kaegler)
    • One of the biggest projects in computing for big science and enterprises these day is computational grids.  Grid computing is at the heart of marketing plans from Oracle, IBM, Sun, and other big companies.  For them, "grid" is mostly a buzzword that describes various ways of tying computers together.  A more specific use of "grid" is found in big science, however.  The national TeraGrid, based on the National Science Foundation's Middleware Initiative (NMI), uses the Globus Toolkit and a variety of other packages to run some of the world's largest supercomputers.  It's also used to tie many smaller computers and clusters together in the academic and business worlds.  Can this "big iron" be hacked?  This talk will examine real and potential weaknesses in Globus and other elements of NMI, as well as the promise and reality of end-to-end security for Grid-enabled computers.
    • AI Transcript

  24. (2004)  Hardware Bus Security in Embedded Systems  - Dan Matthews
    • Surprisingly, every individual comes into contact with over 100 embedded computer systems every day.  A great many exist in our homes without our realizing it and many more operate the commonplace items in the world around us.  An "embedded system" is a self contained miniaturized "computer system" (CPU, memory, I/O) that is dedicated to performing a single type of operation.  They are now common in households through HVAC (Heat Ventilation and Air Conditioning), stoves, refrigerators, televisions, video players, set-top boxes, lawn sprinkler systems, and many other items.  They are in the world around us controlling our street lighting, door openers, intruder alert systems, product theft security, speed cameras, and much more.  The concept of security for these buses is traditionally very low because the designer has always been able to depend on physical security of an enclosed box.  However, as more of the "boxes" are connected together more external buses and networks come into being and more opportunities for access and malfunction, whether through poor design, unforeseen circumstances, or foul play, become possible.  This is a discussion of the progression of design from self-contained systems to more complex ones with internal buses and finally external standard buses.  There will be an explanation of what an embedded system is and examples of complex embedded networks.  Their security, and hence your security, is at risk in many cases, much of it due to "security through obscurity."
    • AI Transcript

  25. (2004)  Homeland Security and YOu: Harry Potter Meets Reality  - Marc Tobias
    • A study of how conference participants can use their expertise to assist private industry and government in assessing vulnerability.  Marc Tobias will present his ideas for a National Security College to train young adults in many topics: crypto, lockpicking, encryption, etc.  He will outline the technical subjects that would need to be taught so students could assist in protecting private sector and government from cyber and physical attack.  Also, a look at some of the potential conflicts students might have in such an environment, including attitudes on intellectual property and its protection.
    • AI Transcript

  26. (2004)  How the Great Firewall Works  - Bill Xia
    • China currently puts in the most effort to censor information on the Internet.  Bill was first involved in freenet-china and started DynaWeb in 2002.  He has developed a thorough understanding of China's Internet censorship technology ranging from IP blocking to DNS hijacking etc.  Various techniques have been implemented to get around them.  There will be an explanation of a censorship algorithm never before publicly released as well as a live demo on how it works.  Time permitting, an analysis of how the Chinese government uses information control on its people will also be presented.
    • AI Transcript

  27. (2004)  How the Net Worked  -
    • The Fifth HOPE network has been in the planning stages for many months.  Did it hold together?  How was it built?  What worked and what didn't?  An open discussion from members of the network crew on what it's like to do something on this scale, some of the hurdles that were faced, ways in which the technology has evolved, and how we can do things differently for future gatherings.
    • AI Transcript

  28. (2004)  How to Break Anonymity Networks  - Nick Mathewson
    • Today's anonymous communication software (such as MixMaster, MixMinion, Nymservers, JAP, Tor, Anonymizer, etc.) allows people to communicate while concealing their identities from each other and from external attackers.  But no deployed system is strong enough to protect every pattern of user behavior against a sufficiently resourceful adversary, and many of them fall to far simpler attacks.  In this talk, Nick will discuss working attacks against today's anonymity networks, drawing from past technical and social attacks on deployed networks and from recent academic research in traffic analysis, stylometry, and mix-net design.  He will present defenses to these attacks when such defenses are known to exist.
    • AI Transcript

  29. (2004)  How to Send Encrypted Email  - Joshua Teitelbaum
    • One day you wake up and you have the sinking feeling that someone may be reading your e-mail correspondence.  Your only recourse is to encrypt or hide your sensitive communications.  This is a look at one web-based solution - CryptoMail - and how it deals with the problem of simplifying encrypted e-mail while maintaining a high level of confidentiality.  A detailed analysis of the CryptoMail session establishment, message encryption, and data store model will be presented.  Furthermore, a demonstration of the working system will be given and attendees may create accounts, ask questions, or comment on the system.
    • AI Transcript

  30. (2004)  How to Talk to the Press  - Stephen Cass
    • Whether you're an activist planning a campaign, a hacker caught in a legal squabble, or just a bystander buttonholed on the street, dealing with journalists can be an essential part of ensuring that your views are heard.  IEEE Spectrum Magazine associate editor Stephen Cass talks about how you can improve your chances of getting a fair hearing.  Topics include understanding what journalists want, interviewee tips, and how to get the attention of news organizations.
    • AI Transcript

  31. (2004)  Incentive Structures: Mechanisms of Control  - Jason Kroll
    • Where do incentive structures come from?  How do political elites use incentives to make us die for them?  How do market elites use incentives to control politicians and co-opt the media?  How can we stop them from doing the same to computing and communications technology?  Why does mankind have to be led through the desert for 40 years every time technology advances?  How are cultural and religious values like computer code and the institutions they create analogous to programs?  How are markets like the AIs in The Matrix?  When mechanisms of control get out of control, we have to ask who really coded Agent Smith and how can we retain control of technology before it comes to that?
    • AI Transcript

  32. (2004)  Indymedia 2004  - Arun Gupta
    • How are hundreds of independent journalists from around the country going to work together to cover the Democratic and Republican National Conventions?  From networks to working groups, from distributed communications such as text message networks and leaflets, and from FTP video transfers to people hawking newspapers on street corners, this session will examine all the tools of organization and distribution that will make these large scale collaborations possible.  Find out how IMCs everywhere have challenged the monopolies of mass media and how this summer in particular will be one of the most active ever for independent media.
    • AI Transcript

  33. (2004)  An Introduction to Dissembler  - Jon Erickson (Smibbs)
    • A presentation of a tool called dissembler, which can be used to generate printable ASCII polymorphic bytecode from any existing piece of x86 bytecode.  The technique used will be explained and the tool will be demonstrated to exploit various sample programs.  Q&A session afterwards.
    • AI Transcript

  34. (2004)  The Kismet Story  - Dragorn (Michael Kershaw)
    • Hear the tale of how the widely acclaimed wireless network detector, sniffer, and intrusion detection system came to be from its creator.  This talk will also focus on how Kismet's development has been shaped by other security tools and users, along with predictions on where it's likely to go in the future.  Also included will be a look at the current state of open wireless drivers and the impact security tools are having on the use of wireless networks.
    • AI Transcript

  35. (2004)  Lockpicking - Part 1  - Matt Blaze, Marc Tobias, and Barry Wels  
    • Lockpicking - Part 2
    • Lockpicking is becoming popular as a sport/hobby among hackers throughout the world.  In a special two-hour session the joy of lockpicking will be explained and demonstrated, from basic techniques to the state of the art.  A whole range of new tools and tricks will be covered.  Many stories will be told including that of Matt discovering a vulnerability in MasterKey systems as well as the members of TOOOL (The Open Organization of Lockpickers - www.toool.nl) discovering a severe vulnerability in a European lock.  This forced a major European lock manufacturer to shut down the factory for a few days and collect a lot of locks from shops.
    • AI Transcript

  36. (2004)  Making Use of the Subliminal Channel in DSA  - Seth Hardy
    • This talk will focus on one reason why it's extremely important to verify the trustworthiness of your encryption programs.  A number of papers about a subliminal channel in the Digital Signature Algorithm (DSA) used by the United States Digital Signature Standard were published more than ten years ago.  This channel allows for undetectable communication via digital signatures.  The subliminal channel is generally viewed as a method of legitimate but hidden communication, but it can also be used for leaking secret information (such as keys) in an undetectable way to anyone who knows what to look for.  This presentation will show how this subliminal channel works and demonstrate - using a patched version of the GNU Privacy Guard - how to use it for both benign and malicious reasons: legitimate communication using the subliminal channel, and leaking secret keys with each signature.
    • AI Transcript

  37. (2004)  Media Intervention via Social and Technical Hacking  - Nathan Martin and Tyler Nordgren (Conglomco)
    • The Carbon Defense League (CDL) and Conglomco are two tactical media arts collectives engaged in both technical and social hacking processes.  Their first collaboration with each other was a website that facilitated barcode relabeling for "user defined pricing."  The site was live at re-code.com before it was shut down by pressure from Wal-Mart, Kellogg's, Price Chopper, and the FBI.  CDL and Conglomco will present details of their past and present projects (including peoplesjeans.com) and discuss alternative tactics for media intervention.
    • AI Transcript

  38. (2004)  Mischief and Mayhem at the RNC  - ShapeShifter (Terrence McGuckin)
    • Back in 2000 at H2K, Bernie S. and ShapeShifter led a discussion on secrets of the major political conventions in the United States.  Not long afterwards, ShapeShifter was arrested on the streets of Philadelphia on suspicion of being a "ringleader" of dissent.  In the end, he won his case against the city and all charges were dismissed.  Like Bernie, his interests weren't squashed because of unjust prosecution.  That's why this panel will focus on the 2004 Republican National Convention taking place across the street from the Hotel Pennsylvania in late August.  The panel will detail how cops spy on people, their methods of surveillance, and how they often abuse authority.  You will learn how to infiltrate organizations like the RNC, how to look for and find security holes, and how mischief and mayhem is achieved.  There will also be details on a unique scavenger hunt.
    • AI Transcript

  39. (2004)  Non-Lethal Technology  - Gonzo DeMann (Michael J. Ferris)
    • Technology is neutral.  The patterns to which it is submitted are what determines if it can be used for betterment or detriment.  This panel will go into that.  As we all know, technology has greatly helped mankind.  But what about technology that has been altered so that it can be used for non-lethal means?  Imagine a bomb that can be dropped that won't kill anyone but will kill any technological related hardware.  How about a blast from a sound wave, or a radio wave that can do physical damage to the body?  These and other topics will be discussed, as will the technology behind it, and sinister applications.
    • AI Transcript

  40. (2004)  Off The Hook Special Broadcast - Part 1  -
    • Off The Hook Special Broadcast - Part 2
    • As part of the $2600 20th anniversary and the HOPE tenth anniversary, we're putting on a special two hour edition of our weekly WBAI radio show live from the conference.  We did a show like this once before at Beyond HOPE in 1997 and it was great fun.  We'll have all kinds of special guests who will visit the stage and we'll have plenty of audience participation.  The show will be transmitted over WBAI 99.5 FM in New York City throughout the entire tri-state region as well as throughout the Internet.
    • A special edition of the program live from The Fifth HOPE, introducing members of the panel, some of the momentous events that all are occurring at the same time, Porkchop reminisces about the editing of Freedom Downtime ($30), this is Kevin Mitnick's first HOPE conference, the hunt for Kevin at the CFP conference in Chicago back in 1993, memories of the various HOPE conferences, Redhackt gives an update on the movie room, Lazlow discusses how corporate radio is causing destruction, Jim talks about his panel at the first HOPE, how MetroCards can be used to track people, Geoff recalls his first experience at HOPE, Mike reveals some of the difficulties involved in creating the HOPE armbands, Jim talks about the new threat posed by Coke cans to national security, the threat of Furbies, the importance of the radio station, an appeal for people to join the station, introducing Juintz, how others can help with the broadcast, ShapeShifter tells the story of what happened to him at the last Republican National Convention, Greg Newby discusses some of what goes into the planning of the conference, Kevin Mitnick talks about his experience at the conference, the connection is lost, Robert Steele talks about the changes since the first HOPE, the risks posed by New York's water system, Bernie S. talks about the usefulness of the CryptoPhone, Jen discusses the thought behind the artwork at the convention, the story of the posters in the windows, Rop compares the hacker conventions of Europe to those of the United States, how the Galactic Hacker Party and Hacking at the End of the Universe inspired the HOPE conferences, plans for a conference in Holland next year, Bernie S. describes the DBS hacking video that will be shown in the movie room, more about the movie room, Chris describes how the A/V came together this time, some listener mail, Porkchop talks about the early days of audio streaming of Off The Hook, Adam gives an update on the status of the network, Dan Morgan stops by, another outage, how the actual connection to the radio station is working, a question about telemarketing, Rebel appears live, Kevin reveals how he was able to call cell phones from prison, how Bernie S. was able to reach the station from prison, other prison phone memories, some of the new material on the Freedom Downtime ($30) DVD, how things are different in Canada, a question from Risctaker, Dan compares his magazine and radio show to those of $2600, some words about "Grand Theft Auto," how the "Free Kevin" message got out to a larger audience, the famous Autumn 1997 cover, how people can become volunteers at the conference, the issue of IP portability, Cheshire talks about his upcoming rants session.
    • Download July 9, 2004 - Part 1
    • Download July 9, 2004 - Part 2
    • AI Transcript

  41. (2004)  Packet Purgatory - Twist Your Packets Before You Set Them Free  - Todd MacDermid
    • Ever wondered what it would be like to have your own custom IP stack readily programmable?  Ever wanted to be able to use stock clients connecting to stock servers, but still be able to tweak the underlying connection?  Have you ever wished you could poke at individual packet bits within a real connection without having to patch your kernel?  Packet Purgatory is a library that allows userland programs to do all of the above portably.  This talk will highlight the development of Packet Purgatory, how to use it, and ideas for future tools.  Also included in the talk will be a discussion of two example tools that have been constructed on Packet Purgatory: StegTunnel, a tool to hide covert channels in TCP/IP connections and LSRTunnel, which spoofs connections using loose source routing.
    • The Design of StegTunnel
    • StegTunnel v0.4  StegTunnel provides a covert channel in the IPID and sequence number fields of any desired TCP connection.  It requires the server and client to have a previously shared secret in common to detect and decrypt the data.  Y;ou don't have to worry about the connections looking unlike real TCP connections, because they are real connections, just with extra info in certain fields.
    • LSRTunnel v0.2.1  LSRTunnel spoofs connections using source routed packets.  LSRTunnel will only be able to spoof connections against hosts that reverse source routed packets.  You can check for this behavior using LSRScan v0.5.1.
    • Loose Source Routing  Why is it still here?
    • What is Packet Purgatory?
    • Packet Purgatory v0.8  Packet purgatory is a userland library that provides an API to a "network wedge" that can sit in between your system's IP stack and the wire.  Outbound packets may be modified after your kernel is done with them, but before they have been send out your NIC, and inbound packets may be modified after they have been received by the NIC, but before the firewall is aware of them.
    • AI Transcript

  42. (2004)  Phreaking in the Early Days  - Captain Crunch and The Cheshire Catalyst
    • Captain Crunch and his friend The Cheshire Catalyst will tell some "war stories" from the early days of phone phreaking.  They'll explain what the Blue Box did, how it was used, and some of their "adventures" in using them.  And kids, don't try this at home!
    • AI Transcript

  43. (2004)  Phone Losers of America  - Murd0c, Rob T. Firefly (Rob Vincent), I-baLL (Leo), Judas Iscariot, and Big-E
    • The Phone Losers of America was created in 1994 as a general hacker/phreaker group.  They eventually started PLA Magazine which in its lifetime released 46 issues (the most recent being a few months ago).  The PLA has done many things over the years, including pulling pranks, operating numerous voice bridges, running their own forums, etc.  This panel will involve a discussion of the history of the PLA, what they are up to now, and the future.  There will also be some videos and sound files presented along with a few "how-to" presentations.
    • Partial Video
    • PLA Media CD
    • Phone Loser of America - PLA Book Project  (PDF)
    • AI Transcript

  44. (2004)  Pirate Radio: Running a Station and Staying on the Air  - b9punk (Jennifer Gergen) and Monk
    • A guide to the setup and operation of a pirate radio station and how to stay on the air when the federal government wants you off.  Monk, founder of KBFR and ongoing benevolent dictator of the group (now over 40 DJs broadcasting 24/7), will moderate this panel on how to beat the authorities at their own game.  Discussion will include types of technologies used to stay a step ahead of the FCC (and some that have failed) as well as more general information on how to set up and run a successful pirate radio operation.
    • AI Transcript

  45. (2004)  Preserving Digital History - A Quick and Dirty Guide  - Jason Scott (Jason Sadofsky)
    • Knowledge doesn't move forward without history and while there have been many steps to capture the stories, lore, and data of different aspects of computer cultures, a lot of the same mistakes are made over and over.  In a fast-paced talk, Jason Scott of www.textfiles.com busts out some ideas, tools, and mindsets towards halting the loss, bringing the stories back, and making something to build upon instead of throw away.  Along the way, expect a few bucketloads of trivia and memories to sauce up the proceedings.
    • AI Transcript

  46. (2004)  Privacy - Not What it Used to Be  - Steve Rambam
    • Steve Rambam has been at every one of our conferences and each time he's outdone himself with tales and demonstrations on how much data is stored on each and every last one of us.  We all hear the news reports about how government and industry want to expand their databases and share all kinds of information.  We hear how people try to protect their privacy and how various organizations attempt to quash the legislation that would broaden these databases.  But what we don't hear is how much of our info is already out there and how much of it is being shared between law enforcement, private industry, and many more.  Steve will share some of his vast knowledge on the subject and leave you feeling terrified and helpless.  And as a special treat, a selected "victim" will learn firsthand just how much personal data can be uncovered on them.
    • AI Transcript

  47. (2004)  Prometheus Radio Project  - Dharma Dailey, Josh Marcus, Hannah Sassaman, and Pete Tridish
    • The Prometheus Radio Project started with radio pirates fighting for local groups to be able to run community radio stations.  But over the years, Prometheus has sued the FCC to stop media consolidation, built stations in places like Guatemala and Colombia, and experimented with using off the shelf wireless technologies to do for hundreds of dollars what commercial stations spend tens of thousands to do.  This panel will help bring you up to date on the political debates in Washington about low-power FM, reforming the spectrum for wireless broadband access, and the grassroots organizing that can be done to reshape the media.  A picture show of community radio barn raisings and stations that Prometheus has worked on around the world will be included.
    • AI Transcript

  48. (2004)  Propaganda in Art and Media  - b9punk (Jennifer Gergen), Mike Castleman, Frederic Guimont, and Lazlow Jones
    • We see propaganda around us every day, some of it a lot more obvious than others.  This panel will show you how to find it and how to make some of your own.  Whether it's something like Frederic's comic book adaptation of George Orwell's 1984 or Mike's "Students For an Orwellian Society" website, you too can have fun with manipulation of the masses.  Lazlow will reveal from the inside how mainstream media strives for control of the masses while b9punk will explain how much of her propaganda art creations came to be displayed at this conference.
    • AI Transcript

  49. (2004)  Retaliation With Honeypots  - Laurent Oudot
    • Most of the time a honeypot is considered to be a security resource whose value lies in being probed, attacked, or compromised.  The purpose of this talk is to explain how honeypots might be deployed not only to use passive defense technologies, but also active defense ones.  As a specific example, think about what might happen the day honeypots are able to automatically strike back at an aggressor or a worm!  Different technical possibilities offered to honeypots on the cyberwarfare field will be explored, such as playing with or even hacking back an usual aggressor (scanner, worm, exploit, client of a Trojan, etc.), improving traceback capabilities to find the real source of an attack, etc.  This will open up all kinds of legal implications which will also be discussed.
    • Honeyd  by Niels Provos
    • AI Transcript

  50. (2004)  Retrocomputing  - Richard Cheshire, Sam Nitzberg, and Steve Wozniak
    • The focus of the retrocomputing panel will be computing technologies from the 1980s and even earlier.  Experiences involving the Altair 8800, the Apple II, and other great machines, their software, and operating systems will be discussed.
    • Slides
    • AI Transcript

  51. (2004)  Steve Wozniak Keynote - Part 1  - Steve Wozniak  
  52. (2004)  Secure Instant Messaging  - Phar (Mike Davis)
    • A look at the evolution of secure instant messaging and how AOL tried to shake off open-source and non-vanilla clients by altering the AIM (oscar) protocol.  The open-source community adapted and readapted until AOL finally gave up.  Phar, who has written the first secure messaging clients for UNIX and Windows (BLAIM and Impasse), will discuss other IM issues, such as the buyout of ICQ by AOL and the subsequent change (and deterioration) of its protocol.
    • Slides
    • AI Transcript

  53. (2004)  Security, Liberties, and Trade-Offs in the War on Terrorism  - Bruce Schneier
    • Since 9/11, we have the PATRIOT Act, tighter screening at airports, a proposed national ID card system, a color-coded national alert system, irradiated mail, and a Department of Homeland Security.  But do all of these things really make us any less vulnerable to another terrorist attack?  Security expert Bruce Schneier evaluates the systems that we have in place post-9/11, revealing which of them actually work and which ones are simply "security theater."  Learn why most security measures don't work and never will, why bad security is worse than none at all, and why strong security means learning how to fail well.  Most of all, learn how you can take charge of your own security - personal, family, corporate, and national.
    • AI Transcript

  54. (2004)  Security Through Automated Binary Analysis  - Dildog (Christien Rioux) and Weld Pond (Chris Wysopal)
    • Automated binary analysis techniques have become sufficiently advanced so that having the source to software is no longer a prerequisite for finding security flaws.  The binary is equivalent to the source.  And a patch is equivalent to a detailed description of a security flaw.  This talk will cover the implications of the latest binary analysis technology and give an overview of some of the technology available.
    • AI Transcript

  55. (2004)  Security Through Diversity  - Javaman (Adam J. O'Donnell)
    • Establishing a diversity of operating systems and software on the Internet is now being viewed as essential to global information security.  This talk will explore how individual systems and large networks can improve their tolerance to massive attack through this principle.  Copies of obscure OS's will be handed out for good questions.  Interpretive dance may or may not be involved.
    • AI Transcript

  56. (2004)  Slaying the Corporate Litigation Dragon: Emerging the Victor in an Intellectual Property Cybersuit  - Atom Smasher
    • Have you ever wanted to tackle a corporate giant and live to tell about it?  Meet web warrior Atom Smasher, whose lifelong fascination with law proved an invaluable commodity the day he found himself in the cross-hairs of some Fortune 500 big guns.  In this lively discussion he'll recount his personal odyssey with the "men and women in black" whose federal lawsuit attempted to pull the plug on his whistle-blowing site.  Learn how he responded to a cease and desist letter, what he did when served with a lawsuit, and how he triumphed in his legal battle.
    • AI Transcript

  57. (2004)  Social Engineering Panel  - Evil Corley and Kevin Mitnick
    • This has always been one of the more popular panels since we started it at the first HOPE in 1994.  And this year, for the very first time, Kevin will be at the conference to be part of the festivities.  He authored a book on the science of social engineering entitled The Art of Deception which was an eye-opener to many in the corporate world.  Emmanuel has been confusing people on the telephone for many years and derives great pleasure out of getting total strangers to give him information he has no right to possess.  In addition to a discussion of methods and stories, be prepared for some live demonstrations over the phone.  Suggestions for good targets are always welcome.
    • AI Transcript

  58. (2004)  Jello Biafra Keynote - Part 1  - Jello Biafra (Eric Reed Boucher)  
  59. (2004)  Tactical Media and the New Paranoia  - Mike Bananno and John Henry
    • The Institute for Applied Autonomy (IAA), The Yes Men, and the Critical Art Ensemble (CAE) are activist collectives that use unconventional means to deliver their message.  The IAA is an anonymous collective of artists, hackers, and radical engineers who have produced projects such as high speed graffiti-writing robots and map-based websites that help people avoid surveillance cameras.  The Yes Men have gained international notoriety for their use of extreme social engineering in order to impersonate World Trade Organization officials at conferences, on the web, and on television.  A feature length film documenting their antics will be released by United Artists in August.  The Critical Art Ensemble is a collective that explores the intersections between art, technology, radical politics and critical theory.  Their books including Electronic Civil Disobedience and The Molecular Invasion have been translated into 18 languages and are used in universities the world over.  Recently the FBI has accused the group of bio-terrorism.  Due to the ongoing investigation, members of CAE are unable to speak publicly on these issues.  However, members of IAA and The Yes Men will describe the events of the case and discuss it as it relates to investigations of hackers.
    • AI Transcript

  60. (2004)  Technology in Romania  - Catalin Acio
    • An overview of the ten year period in Romania from 1989 to 1999 and the challenges involving access to technology, the perception of IT in the formerly communist country, and issues of freedom of speech and information.  Ninety percent of all access to the Internet is still done via timed dial-up connections which makes connectivity much harder for programmers, researchers, and the average citizen.  Learn about the differences in technical cultures and what is being done to level the playing field.
    • AI Transcript

  61. (2004)  Ten Years of Practical Anonymity  - Len Sassaman
    • Strong anonymity systems have been available for public access on the Internet for the last decade.  During this time the Internet landscape has changed considerably, while the body of knowledge in the field of anonymity research has deepened greatly.  This talk will review the history of anonymity systems, describe the methods by which modern anonymity systems protect their users, explore the classes of attacks which exist against anonymity systems, and give examples of practical anonymity systems which can be freely and easily used by the public at large.  Emphasis will be placed on e-mail anonymity and the long-lived anonymous e-mail software Mixmaster and the associated remailer network, though other forms of Internet access anonymization will be included for discussion.
    • AI Transcript

  62. (2004)  Terrorism and Hackers  - Greg Newby
    • This presentation will put forth a full range of activities in which hackers can apply their skills to achieve goals related to "the systematic use of violence to create a general climate of fear in a population and thereby to bring about a particular political objective" (britannica.com).  This range includes many specific ways for hackers to combat terrorism, methods to fight terrorist tendencies of your country, and how hackers might actually participate in terrorism.  Despite being demonized by corporate media and the subject of many recent laws, most hackers, like most people of all types, are not terrorists.  What can we do to protect against hackers being misperceived as threats and terrorists?
    • AI Transcript

  63. (2004)  Today's Modern Network Killing Robot  - Viki Navratilova
    • This is an overview of the new generation of DDoS tools.  Back in the day, a couple of large pings could take down lots of machines.  When those techniques stopped being effective means of taking down networks, people started writing DDoS programs.  These programs required a little bit of manual work to install, but were effective at taking down large networks for a while.  This generation of DDoS tools was made famous in the media for victimizing famous websites for hours at a time.  Soon people learned to control the damage done by these tools, and so a new generation of DDoS tools was born: Ones that could infect thousands of machines automatically to create large botnets and hide their communications in order to evade detection better than their predecessors.  These botnets are now the most effective DDoS tools in popular use today.  This talk will go over the more popular botnets, such as gtbot and sdbot, and talk about how they work and some ways to spot them on your network.  There will be a demonstration of an irc botnet in action.
    • Note:  The recording of this panel is incomplete, though we've posted what we have.  Please accept our apologies.
    • AI Transcript

  64. (2004)  Urban Exploring: Hacking the Physical World  - John & Laura Leita
    • Urban exploring is the art of going places off limits to most and unseen by many.  Explorers are brave souls who often dredge through great dangers for their art.  Often they research and document historic abandoned places to accompany pictures and video taken on the locations of sites with enormous history.  Otherwise they are simply in search of a beautiful view.  John and Laura will talk about the different locations of interest to urban explorers, such as abandoned asylums, steam tunnels, rooftops, abandoned rail spurs, former used industrial sites, and deserted gold coast estates.  From there they will go into how this art is best performed and various associated issues.  Topics will include how to find urban exploration sites, how to go about exploring and documenting them, UE photography and video, computer assisted exploring, and research techniques to learn about a site.  A video CD presentation will be shown to illustrate urban exploring and show some cool places.
    • AI Transcript

  65. (2004)  When Corporations Attack  - Acidus (Billy Hoffman), Virgil Griffith, Dan Morgan, and Wendy Seltzer
    • We all know the wrath that major corporations are capable of unleashing when the actions of hackers and other individuals anger them.  This panel will focus on two of these cases.  Dan was the publisher of Satellite Watch News, a publication that focused on the technical workings of the satellite industry.  DirecTV (owned by General Motors) managed to completely shut down the newsletter and take nearly all of his possessions.  Acidus and Virgil did research into the Blackboard college ID card system (used at universities everywhere) and they uncovered all kinds of interesting facts.  This was to be presented at the Interz0ne conference in Atlanta in 2003.  Blackboard filed an injunction that not only kept that from happening but has prevented the two from discussing specifics about Blackboard to this day.  In addition to these three panelists, a representative of the EFF will be on hand to talk about the legal aspects of these frightening cases.
    • AI Transcript

  66. (2004)  Where'd All That Spam Come From?  - John Draper
    • A study of the mechanisms spammers use to flood your mailbox along with what some of the work and research of SpamCrunchers have uncovered.  Topics of this talk will include spam bots, spam Trojans, some of the sneaky methods spammers use, how they get around filters, why none of this stuff really works anyway, and what you can do to significantly cut down on spam.
    • AI Transcript

  67. (2004)  Wireless and Wi-Fi: The Good, the Bad, and the Ugly  - Dragorn, IrishMASMS, Mike Lynn, and Porkchop (Michael Kaegler)
    • A panel to discuss wireless networking: the basics of 802.11 and current products, along with stories of wardriving and a look at network security.  Find out why you should care about your network's security even if you don't think anyone else would take an interest in your traffic.  Questions and comments from the audience will be solicited.
    • AI Transcript

  68. (2004)  Closing Ceremonies  -
    • Another one of our traditions is to gather everyone together in one room and bid farewell until next time while summarizing some of the highlights of the last three days.  This is also where we give away various prizes to audience members.  If you're one of those people who booked your return trip for Sunday afternoon, you'd best get on the phone and change those plans.  The weekend ends Monday morning, after all!
    • AI Transcript



HOPE Number Six





  1. (2006)  $2600 Meetings: A Valuable Resource or a Waste of Time?  - Rop Gonggrijp, Evil Corley, LexIcon, and others  
    • Since they began in 1987, $2600 meetings have sprung up all around the world.  They inspired the movie Hackers.  Helped to launch a number of federal and state investigations, provided journalists with fodder for all sorts of wild and crazy stories, and brought all sorts of hackers together who might otherwise never have met.  But is this a good thing or a bad thing?  Do the meetings actually strengthen the community or do they expose it to hostile elements that help to destroy it?  You will hear a number of perspectives as well as stories on things that have happened at the many meetings that have taken place.  If you've ever attended a $2600 meeting, we'd like to hear your feedback at this panel.
    • AI Transcript

  2. (2006)  Aether Madness with the Prometheus Radio Project  - Dharma Dailey, Andy Gunn, Hannah Sassaman, Pete Tridish, and Anthony Mazza  
    • The Prometheus Radio Project started with radio pirates fighting for local groups to be able to run community radio stations.  Over the years, Prometheus has sued the FCC to stop media consolidation, built stations in places like Venezuela and Tanzania, and experimented with using off-the-shelf wireless technologies to do for hundreds of dollars what commercial stations spend tens of thousands for.  Prometheus fights for change by going straight to the pileup where technology, politics, and the media crash into each other.  This panel will help bring you up to date on the political debates in Washington about low-power FM, reforming the spectrum for wireless broadband access and other uses, and the grassroots organizing that can be done to reshape the media.  A picture show of community radio barnraisings and stations that Prometheus has worked on around the world will be included.
    • AI Transcript

  3. (2006)  Alienation and Engagement  - Jason Kroll  
    • The hacker sense of social responsibility is undermined by our alienation from the mainstream.  From bad school experiences in childhood to the content property grab of today, we infer the world to be hostile and corrupt.  Unwilling to become sociopaths, yet unable to find avenues for social change, we are tempted to withdraw from civil society and limit ourselves to technical contributions.  A discussion of three non-technical areas where hackers can make positive contributions and where we might find principled people: journalism, economics, and law.  The next civic establishment has to come from somewhere and this should be our historical era.  So we might as well participate - or maybe just take over.
    • AI Transcript

  4. (2006)  The Art of Electronic Deduction  - StankDawg (David Blake)
  5. (2006)  Basics of Forensic Recovery  - Kall Loper  
    • This presentation will introduce the basic model for forensic recovery of data in civil and criminal contexts.  Technical challenges of acquisition and analysis will be briefly covered but the primary emphasis will be on the requirements of bringing data to court.  Common tools will provide examples to illustrate the model.  There will also be a brief discussion of provisions of the enforcement mechanisms of the Digital Millennium Copyright Act and recent case law dealing with failures to comply with production of evidence.
    • AI Transcript

  6. (2006)  Binary Revolution Radio  - StankDawg and Guests  
    • Binary Revolution Radio is a weekly Internet radio show that has been around since early 2003.  The show covers topics that are of interest to the hacking community including hacking, phreaking, programming, digital rights, social engineering, and everything in between.  The beginning of season four of this show coincides with HOPE Number Six this year and this will be an episode of the show recorded in front of a live studio audience!  There will be lots of special guests, audience participation, and maybe... just maybe... punch and pie.  You have to show up to experience it live and see why "The Revolution Will Be Digitized!"
    • Binary Revolution Radio
    • AI Transcript

  7. (2006)  bin Laden, National Intelligence, and How NOT to Spend the Taxpayer's Treasure  - Robert Steele
    • This presentation will address the Ten Threats, Twelve Policies, and Eight Challengers.  And if you want to find out what all that means, you'll just have to attend.  Robert was our keynote speaker at the original HOPE in 1994 (and our very first speaker ever) and has continued to rivet audiences ever since with stories and facts about national intelligence.
    • AI Transcript

  8. (2006)  Breaking Down the Web of Trust  - Seth Hardy  
    • The web of trust best known for its use in PGP is now used in a number of other applications and is established as a good method for doing non-centralized PKI.  But how good is it?  How does one define a metric for trusting a trust metric?  We have key signing parties and extensive tutorials on good trust policies, but a lot of people still don't understand the basic concept of "trust," especially when it is superimposed on the world of graph theory.
    • Seth will take a look at the web of trust as it is currently used, including statistics on the PGP WoT and what that means in practical terms.  And from there on, it's all about trust, including the trust metrics involved (and why they could be a lot better) and the current "correct" practices for establishing trust (and why they could be a lot better).  To finish, Seth will talk about some of the many bad trust policies that have managed to become mainstream and commonly accepted, even by many self-described "computer security professionals."
    • AI Transcript

  9. (2006)  Building a Hacker Space  - Porkchop (Michael Kaegler), Harry Hoffman, Dragorn (Michael Kershaw), and Nick Binary (Nick Amento)  
    • By pooling resources, hackers can get bigger and more impressive toys to accomplish bigger and more impressive projects.  This talk focuses on setting up and managing collectives for fun and profit - from finding a space to keeping it going.  Presented by people who did it in Massachusetts, New York, and Pennsylvania.
    • AI Transcript

  10. (2006)  Building the Anti-Big Brother Databases  - Peter Wayner  
    • Databases don't need to be huge collections of personal information waiting to be exploited.  This talk will show how a few simple encryption functions can build a database that answers questions for the legitimate users but locks out all illegitimate users including those with the root password.  The techniques make it possible to build privacy-preserving systems with much less complexity and overhead than conventional techniques.
    • AI Transcript

  11. (2006)  Can Security Detectors be Hacked?  - Paul Renda  
    • Today we are challenged by a multitude of security detectors.  But can they be beaten?  This talk will deal with their vulnerabilities.  The electromagnetic spectrum will be explained along with how waves propagate.  Security systems like X-ray backscatter and millimeter-wavelength microwave will be discussed along with possible defenses.  Most of the talk will focus on the ubiquitous metal detector - the walk-through and handheld variety.
    • The question of whether radio frequency devices can compromise security will be explored.  Front door and back door attacks (coupling modes) will be defined.  The urban myth of radio frequency devices/weapons will be discussed.  It will all top off with a discussion of Carl Jung and King Hubbert and how they relate to terrorism.
    • This talk is dedicated to Paul's cousin Tommy Farino, a New York Fire Department captain who died on 9/11.
    • AI Transcript

  12. (2006)  Citizen Engineer - Consumer Electronics Hacking and Open-Source Hardware  - Phillip Torrone and Ladyada (Limor Fried)  
    • This is a hands-on session on all the things you're not supposed to do (but want to) with the gadgets that fill our drawers and shelves: transform an old VCR into an automatic cat feeder, use open interfaces to control Roomba robotic vacuums.  Projects like these (and others, such as WRT54G hacking, iPod Linux, car-computer hacking, etc.) are part of a growing trend where consumers are going back and hacking what they buy.  Just as computer hacking is closely tied to the open-source software movement, so can such embedded gadget-hacking lead to an open-source hardware movement.
    • AI Transcript

  13. (2006)  Comparison of WAN Routing Protocols  - Miles Nordin  
    • A comparison of three members of a class of WAN routing protocols called "interior gateway protocols."  Each member of the class - RSTP, OSPFv2, and IS-IS - is bound to a different kind of datagram: Ethernet frames, IP packets, and OSI CLNP datagrams respectively.  Most companies with large WANs use one of the first two protocols for two purposes: to route around failed redundant links and to automatically find the correct path to a destination address on a large network with many hops.  Including RSTP in the comparison is a realistic acknowledgment of the way L2 switching is abused these days.  Including OSI in the comparison should reveal some habitually irritating aspects of switched IP networks that are mere accidents of history, and others that are more fundamental.  Miles will provide background about how Ethernet switching works, what an IGP is, and what the now mostly-abandoned supposed-future OSI world feels like.
    • AI Transcript

  14. (2006)  Constructing Cryptographic Protocols  - Joe Salvatore Testa II  
    • This lecture will show how to construct advanced cryptographic protocols.  Beginning with a set of requirements for a communications protocol that includes immunity from replay attacks, traffic analysis resistance, and resiliency against partial compromise, the audience will be shown how a naive protocol can be iteratively improved into a protocol satisfying those requirements.
    • AI Transcript

  15. (2006)  Coupon Hacking  - Sam Pocker  
    • The price of everything has become too expensive.  As retailers feel they need to cater to the lowest common denominator, you are held prisoner in artificially antiseptic environments, customer service is a mockery of intelligent discussion and basic common sense, and yet somehow we now live in a consumer-driven economy.  This presentation attempts to provide an understanding of how you can fight back - how to understand what you are really seeing when you walk into a supermarket, a "big box" mass merchant retailer, or even a local mall.  It will also address "coupons," how you can read the barcodes with the naked eye and decipher them, and how you may use them to get nearly anything for free, or almost free.
    • AI Transcript

  16. (2006)  The CryptoPhone Project  - Frank Rieger and Barry Wels  
    • In 2003 a group of enthusiasts turned a standard PDA phone into a military grade voice encryption device.  Unlike other players in the secure communications market, CryptoPhone decided to publish the complete source code for review.  Not only that but a software-only client that will turn your PC and modem into a CryptoPhone is available for free download.  The product range has expanded to landline and satellite solutions.  What is next?
    • AI Transcript

  17. (2006)  E-gold - As Misunderstood as Hackers  - Richard Cheshire, and Oddsman (James M. Ray)  
    • Internet Commerce is a wonderful concept.  So is Internet privacy.  They clash where the government can access private bank records.  E-gold allows private transactions to remain private.  Unfortunately the Bad Guys want their transactions to be most private, giving e-gold and their financial brethren a bad reputation.
    • AI Transcript

  18. (2006)  Exploring Your World with Open-Source GIS, GPS, and Google Maps  - Mike Dvorak and Paul Suda  
    • Digital mapping is the ideal information sharing medium for urban explorers, war walkers, and travelers alike.  Powerful open-source geographical information system (GIS) software such as GRASS exists for users of all computer platforms to explore, analyze, and digitize custom maps.  A brief overview of mapping will be given and then GRASS will be used to demonstrate how to make an annotated bike trip map around New York City.  The Google Maps API for making customized maps will also be explained and demonstrated.
    • AI Transcript

  19. (2006)  Europe Has Hackers Too  - mc.fly (Elmar Lecher), Frank Rieger, and Rop Gonggrijp  
    • There are hackers on the other side of the pond too!  This is a view of parts of the European hacker scene, especially that of Germany and the Netherlands.  The Chaos Computer Club will be discussed along with other European hacker groups.  You will learn about the major differences between the American and European hacker scene, see what the different lifestyles are like, and get a good look at some of the European hackers' nicest projects.  There will also be details on upcoming European conferences which you are cordially invited to.  After the presentation an open discussion will permit you to ask any questions about all of those fancy countries on the other side of the pond.
    • AI Transcript

  20. (2006)  Everything You Ever Wanted to Know About Spying and Intelligence - Part 1  - Robert Steele  
  21. (2006)  Flash Sucks for Advertisers - The Digital Divide  - Richard Cheshire, and Gerald Greene  
    • While the contention is that Macromedia Flash sucks for consumers who can't download Flash, it actually means that the advertisers using it are not getting their message out to those consumers.  This will be a discussion of Internet access and The Digital Divide, with emphasis on the Internet's role in special education.
    • Notes
    • AI Transcript

  22. (2006)  The Future of Wireless Pen-Testing  - Dragorn, Frank "Thorn" Thornton, and RenderMan (Brad Haines)  
    • The future of wireless pen-testing and vulnerabilities of 802.11 networks, RFID, and Bluetooth, including a then-and-now perspective of the past five years of development in wireless vulnerabilities and research, pet peeves, the future of wireless protection standards, and topics from the audience.
    • AI Transcript

  23. (2006)  The Geek Comedy Tour 3000  - Chris Barylick, Frank Hong, Jimmy Meritt, Justin Schlegel, Evan Valentine, Danny Rouhier, Joe Deeley, Paul Schorsch, James Jones, Erin Conroy, and Ryan Conner  
    • Picture what happens when you give the kids who were picked last for dodge ball a microphone and some stage time.  The Geek Comedy Tour 3000 is just that.  A collection of some of the best standup comedians from the Washington, D.C. area, this group comes to the stage with a high-energy approach as well as topical, intelligent material that is accessible to both techies and non-techies alike.
    • AI Transcript

  24. (2006)  The Geeky, Personal, and Social Impact Sides of Creating Defensive Technology  - Mitch Altman and Ladyada (Limor Fried)  
    • Ever wish you had the power to turn off a TV in a restaurant or disable an intrusive cell phone?  Social defensive technologies are "reality hacking" devices that give us the sort of sociopathic control we've come to enjoy on the Internet alone.  Three years ago, Mitch decided he'd had enough of televisions and designed the TV-B-Gones, a universal "off" keychain remote.  Around the same time, Ladyada designed a personal RF jammer.  Together they will discuss these projects in the context of reclaiming personal space, culture-jamming, and how we can design technologies that do what we really want.  Don't expect good Wi-Fi/cell reception.
    • AI Transcript

  25. (2006)  Ghosts (and Zombies) in the Machine  - Brad Johnson  
    • What do dark fiber, zombie networks, web ghosts, and net spooks have in common?  They're all scary!  Boo!  Come for a fun and wide-ranging survey of largely unrelated Internet phenomena, from computers zombied by script-kiddie rootkits to MySpace pages and blogs left after their creators have died.  Is there really a ghost in the machine?  Maybe not, but there's definitely a lot of bizarre stuff around the edges.
    • AI Transcript

  26. (2006)  Hack the Palate!  How to Set Up a Kitchen Hack Lab  - Gweeds (Guido Sanchez)  
    • Chefs are a lot like hardware hackers.  Both geek out, absorbing the specs of vegetables/technology for the purpose of creating something that nobody else has: innovative food/new machines).  So what kind of food comes out of a kitchen that's turned into a hack lab?  Something delicious.  Something geeky.
    • AI Transcript

  27. (2006)  Hackers and Academia  - Adam J. O'Donnell (Javaman), Matt Blaze, and Gillian Andrews  
    • In many ways, the hacker community and the academic community don't appear to get along.  The classical view of how both academia and the hacker community operate seemingly are mutually exclusive, with the academy priding itself on rigor and proof while the hacker community espouses a "proof by example" methodology.  The relatively slow pace of academia turns off hackers, and the lack of rigor of hackers does the same for academics.  During this panel discussion, we show how the two worlds are not that far apart and present individuals who are actively trying to bridge the gap between the two.  Current students, past students, professors, and hackers, one in the same, will be present for the discussion.
    • AI Transcript

  28. (2006)  Hackers in Prison  - Mark Abene (Phiber Optik), Bernie S., and Kevin Mitnick  
    • For the first time ever, the three most famous imprisoned hackers of the 1990s appear together on the same panel.  Mark served ten months in 1994, bernieS was locked up for 14 months in five maximum security prisons in 1995 and 1996, and Kevin was held for nearly five years.  Each of these cases received a lot of exposure from $2600 and Off The Hook which wound up getting the attention of mass media and the public.  But these cases are only the tip of the iceberg.  You'll hear some of the background, learn about what's going on today with some other cases, and maybe even hear some prison stories.
    • Kevin Mitnick unfortunately wound up in a hospital in Colombia for the entire conference and is replaced here by Darci Wood.
    • AI Transcript

  29. (2006)  Hacking Copyright and Culture  - Fred Benenson
    • Taking things apart, reusing, and remixing the old in order to create the new are tenets of the hacker ethic.  But these impulses have also been at the heart of artists, musicians, and writers since the beginning of human creativity.  Complete access to copy, reuse, and remix work is necessary for cultural and technological progress, a progress that the current state of copyright and the increasing ubiquity of DRM threatens to permanently undermine.
    • This fight has become political.  From protests to boycotts, from lobbyists to students, there is a movement underway and an increasing number of ways to get involved and fight for your digital rights beyond sending $15 to the EFF and running GNU/Linux (which you should already be doing).
    • This talk will be about the current state of the free culture student movement and events being organized in the area, including the first ever anti-DRM protests, a Creative Commons art show, and a DVD remix contest.
    • AI Transcript

  30. (2006)  Hacking the Mind: Hypnosis, NLP, and Shellcode  - Mike Murray  
    • The similarities between the methods used to exploit a computer network and the language patterns involved in hypnosis and Neuro Linguistic Programming (NLP) are striking.  In this talk, nCircle's director of vulnerability research Mike Murray (who is also a Master NLP practitioner and certified clinical hypnotherapist) will demonstrate the use of hypnotic language patterns, metaphors, and other patterns of influence, as well as showing how a good hypnotist structures inductions in a similar way to the methods of a skilled computer hacker.  Hypnotic analogues to buffer overflows, shellcode, and other types of computer attacks will be demonstrated, leaving the audience with a deeper appreciation for language patterns and their effect on the human mind.
    • Slides
    • AI Transcript

  31. (2006)  The HOPE Net: What Worked and What Didn't  - Dragorn, Doug
    • This is where we review what it took to put the network together.  There are bound to be some fascinating stories to share as far as what went on over the weekend.  This network is by far the biggest ever attempted at any hacker conference on this side of the ocean with more bandwidth available than many countries have.  This makes the stories even more entertaining.  The network gurus of HOPE will have a lively discussion on the challenges of running a network at a hacker conference right before it all gets taken apart.
    • AI Transcript

  32. (2006)  How to Steal Someone's Implanted RFID - And Why You'd Want To  - Annalee Newitz and Jonathan Westhues  
    • Annalee Newitz will talk about how she got a RFID implant to demonstrate some of the basic security problems with these devices.  These are problems that the companies who make RFID systems are either ignoring or outright lying about.  She'll discuss the process of implanting the RFID, including getting the surgery and unpleasant dealings with VeriChip.  She will also talk about the many problems with security used for implanted RFIDs (and security problems with RFIDs used as access control devices).  Then Jonathan, the RFID-hacking expert who cloned Annalee's RFID, will talk about how he did it and (hopefully) he'll be able to give a demo.  He'll describe how he made his device and how it can also be used for proximity card cloning.  He also has a new cloner which he may or may not want to talk about in detail.
    • AI Transcript

  33. (2006)  How to Talk to the Mainstream Media  - Stephen Cass  
    • Blogs, vlogs, podcasts, RSS, even old-school web sites and mailing lists - there's never been more ways for hackers to get their message out.  So why bother dealing with the Mainstream Media?  Because that's where the audience is.  Only a tiny percentage of blogs have sizable audiences and even the biggest of those are dwarfed by the audiences for TV news, mainstream media websites, or the circulations of the larger dead-tree newspapers and magazines.  If you're interested in getting your point across to as many people as possible, this talk will improve your chances by telling you what professional journalists want and why, how you can help give it to them, as well as what pitfalls to avoid.
    • AI Transcript

  34. (2006)  IBOC vs. DAB-T: In-Band vs. Multiplexed Digital Radio  - Russell Trafford-Jones  
    • More and more U.S. stations are going digital using "In-Band On-Channel" methods where the data is sent with the analog radio station.  But a lot of the rest of the world uses a different frequency for the digital version of the station.  This talk describes the transmission methods technically, discusses the pros and cons of the different methods as well as the commercial implications, and focuses on how community radio can fit into the changing landscape of radio.
    • Will the U.S. and its listeners lose out by using different systems than most other countries?  A look at this question, why IBOC has been adopted, and how digital radio helps and hinders reception.
    • AI Transcript

  35. (2006)  Richard Stallman Keynote  - Richard Stallman  
    • "Free Software and the Hacker Community"
    • Talking about software rights, except for the right for you to do what you wish with your own code.
    • AI Transcript

  36. (2006)  Michael Hart Keynote  - Michael Hart  
    • Using eBooks to break down the bars of ignorance and illiteracy.
    • AI Transcript

  37. (2006)  Jello Biafra Keynote  - Jello Biafra (Eric Reed Boucher)  
    • Hacked by Uncle Sam, vote fraud, and the end of democracy.
    • AI Transcript

  38. (2006)  Law Enforcement Wiretaps: Background and Vulnerabilities  - Micah Sherr, Eric Cronin, Sandy Clark (Mouse), and Matt Blaze  
    • The politics of wiretapping is a hot topic (again) lately.  But how do the police actually tap telephones anyway?  How might tapping technology fail?  Telephone wiretap and dialed number recording systems are used by law enforcement and national security agencies to collect critical investigative intelligence and legal evidence.  This talk will examine the technology of (legal) wiretapping and show how many of these systems are vulnerable to simple, unilateral countermeasures that allow wiretap targets to prevent their call audio from being recorded and/or cause false or inaccurate dialed digits and call activity to be logged.  An exploration of possible workarounds, as well as the broader implications of the security vulnerabilities in evidence collection systems.
    • AI Transcript

  39. (2006)  The Life and Times of Alan Turing, Father of the Computer  - Karamoon  
    • Alan Turing was an intriguing guy whose life was as tragic as it was amazing.  Known as the father of the computer, the man who broke the Enigma code, and a sad victim of British homophobia in the 1950s, Turing serves as a role model for many hackers, computer scientists, and mathematicians.  This talk tackles three subjects: Turing's role in breaking the German Enigma code, Turing as the father of the computer, and Turing's personal life (and death).  A look at Turing's life in chronological order, focusing on events which had profound effects on his thinking and feelings.  Turing's story is ultimately a sad one, but along the way you'll see a breakthrough in cryptography and the birth of the computer.  You'll also want to fight much harder for freedoms that we still take for granted, despite the fact that they are disappearing fast.
    • AI Transcript

  40. (2006)  Lockpicking: Exploits for Mechanical Locks  - Barry Wels and Marc Weber Tobias  
    • Every mechanical lock, no matter how sophisticated, can be bypassed.  And here you will learn how.  A wide variety of opening techniques will be demonstrated.  Ranging from "lock decoders" that are in use by the intelligence community to till tools and techniques that allow a layman to open a wide variety of locks with little training and using only inexpensive tools.  Even the opening of some state of the art electronic locks will be demonstrated on stage.  If you're willing to learn then simply join one of the training sessions during the conference (in the lockpick village) to have Barry and his friends teach you how to pick and bypass locks yourself.  You are invited to bring your own locks and find out if they are any good.
    • AI Transcript

  41. (2006)  Low-Level Firmware Analysis and Hacking  - John Maushammer (Morchiba)
    • A presentation using examples from John's experience reverse engineering disposable digital cameras.  Hardware disassembly, reading firmware from the flash chip, firmware disassembly, figuring out hardware registers, and how to identify and circumvent lock codes will be among the topics touched upon.  The CVS camcorder lock and the vulnerability that hacked it will also be discussed.
    • AI Transcript

  42. (2006)  Magnetic Stripe Technology and the New York City MetroCard  - Joseph Battaglia  
    • Curious what's on all those magnetic stripes in your wallet?  Learn how magnetic stripes work and how you can use parts from your "junk drawer" to build a simple reader.  Joe's reader design is easy to build and is capable of reading proprietary formats that most commercial readers can't.  The software, which runs under Linux and requires only a sound card, does most of the work and is easy to tweak.  Also included in the lecture will be a discussion about the New York City MetroCard and how its proprietary encoding was reverse engineered with this reader design.
    • AI Transcript

  43. (2006)  Making Reliable Links Using Wi-Fi  - Catonic Cinotac  
    • Ever wondered exactly how much engineering goes into professionally installing Wi-Fi links to 99.999 percent availability?  In this talk, Catonic will be covering calculating path loss, Fresnel zones, gain, power, and other topics which when combined are used to design RF links between two locations.  The information in this talk is useful for VHF, UHF, and microwave link planning.  Additionally, Catonic will be providing an analysis of some of the factors considered when iFiber Redwire planned and then executed last year's record Wi-Fi shot of 125 miles.
    • GBPPR Microwave Radio Path Analysis
    • AI Transcript

  44. (2006)  Managing Your Company's Intellectual Property: An Introduction to IT Security  - Daniel Estrada  
    • Data is every company's most valuable asset and its protection is imperative for survival.  This presentation gives managers and other business leaders the practical foundation they need to secure their intellectual property, properly comply with legislative requirements, and maximize the overall value their IT strategies provide.
    • AI Transcript

  45. (2006)  The Monochrom Collective  - Johannes Grenzfurthner, and Roland Gratzer
    • A talk medley from monochrom, a worldwide operating collective from Vienna dealing with technology, art, context hacking, and philosophy which was founded in 1993.  They specialize in an unpeculiar mixture of proto-aesthetic fringe work, pop attitude, subcultural science, and political activism.  Their mission is conducted everywhere, but first and foremost "in culture-archaeological digs into the seats (and pockets) of ideology and entertainment."
    • This session will be a little tour-de-farce about their projects and political motivation.  A joyful bucket full of good clean fanaticism, crisis, language, culture, self-content, identity, utopia, mania and despair, condensed into the well known cultural technique of a gala show.
    • Among their projects, monochrom has released a leftist retro-gaming project, established a one baud semaphore line through the streets of San Francisco, started an illegal space race through Los Angeles, buried people alive in Vancouver, and cracked the hierarchies of the art system with the Thomann Project.  In Austria they ate blood sausages made from their own blood in order to criticize the grotesque neoliberal formation of the world economy.  Sometimes they compose melancholic pop songs about dying media and they have hosted the first annual festival concerned with cocktail robotics.  At the moment they're planning a conference about pornography as one of the driving forces of technological innovation.  They also do international soul trade, propaganda camps, epic puppet theater, aesthetic pregnancy counseling, food catering, and - sorry to mention - modern dance.
    • AI Transcript

  46. (2006)  Network Monitoring and the Law  - Alexander Muentz  
    • A discussion of federal and state criminal law as well as civil penalties, expectations of privacy at work, and the relative rights and duties of employers, employees, and IT workers.  Also included will be an explanation of network monitoring and the Wiretap Act.
    • A New Era of Telecommunications Surveillance
    • AskCALEA  Mirror of askcalea.fbi.gov
    • AI Transcript

  47. (2006)  The New Engineers of Graffiti  - James Powderly, Evan Roth, Theodore Watson, and Evan Harper  
    • The Graffiti Research Lab is dedicated to outfitting graffiti writers, street artists, and protesters with open-source technologies for urban communication.  The goal of the GRL is to technologically empower individuals to creatively alter and reclaim their surroundings from unchecked development and corporate visual culture.  During 2006, the GRL has toured across the globe demonstrating and teaching new graffiti technologies and DIY skills to diverse public audiences.  Their work has been featured in alternative and mainstream news sources like the New York Times, Wooster Collective, TIME Magazine, Visual Resistance, and The Village Voice.  In May 2006, Ars Electronica gave the Award of Distinction in Interactive Art.  You can find their work at www.graffitiresearchlab.com.
    • This panel will give an introduction to geek graffiti and focus on the Eyebeam OpenLab with particular attention to public domain DIY hardware hacking, GNU software, and Creative Commons content.  Some GRL tools will include LED "throwies," the "night writer," the "electro-graf," and more.
    • AI Transcript

  48. (2006)  Off The Hook - The Indecent Version  - Featuring the Off The Hook Cast  
    • Yes, that's right, the acclaimed WBAI radio show does an edition that the FCC won't permit us to air.  Restrictions on what we're allowed to say over the radio will be addressed in a very "direct" manner.  Over the years the American broadcast media has become increasingly government-controlled with the federal authorities determining what is decent and what is not.  The result has been a whole lot of blandness and conformity, not to mention a good dose of fear and paranoia behind the scenes.  While we may not be allowed to say a lot of things over the air, we can say them in a room full of people.  At least for now.  One day perhaps this edition will be allowed to be heard on the radio.  For now, though, you can win a prize by figuring out just how much we could be fined and imprisoned if this show were to make it to air.  In all honesty, we believe it will be a pretty "decent" hour.  You can even bring the kids.
    • AI Transcript

  49. (2006)  Password Cracking and Time-Memory Tradeoff  - Jason Davis  
    • An in-depth explanation of the applications of time-memory tradeoff when applied to password cracking and its relevance to the future of the IS industry.  Also, a demonstration of what quite possibly could be the fastest web-based MD5 password cracker on the planet.
    • AI Transcript

  50. (2006)  Phone Phreaking 101  - Black Ratchet (Ben Jackson)  
    • Have you ever caught yourself thinking "Gee, I wonder how this phone thingy works?"  Do you often dream about what's inside that building downtown with your local phone company's logo emblazoned upon it?  Do you find yourself confused when people start talking about "op-diverting," "setting up 8s," or "getting on the bridge?"  If so, then this presentation is for you.
    • Ever since the early 1990s, most people have thought that phone phreaking was dead.  They have thrown their Black, Red, and Blue Boxes out with their trash and have dismissed the idea of "phone phreaking" with the same zeal that they dismissed the idea of the Easter Bunny and Santa Claus.  But phone phreaks still survive to this day!  The phone network was one of the first great networks.  Yet today it just sits there, only explored by a handful of people.
    • This presentation is an attempt to change all that.  It will answer basic questions and clear up common misconceptions about phreaking, the phone system, and telephony in general.  It will also attempt to clear up urban legends that continue to exist today and show people that phreaking is not a dead art.  Topics covered will include history, basic phone network operation, VoIP, myths and misconceptions, general phreaking, and stupid phone tricks.
    • AI Transcript

  51. (2006)  Privacy is Dead - Get Over It - Part 1  - Steven Rambam, Gerard P. "Jerry" Keenan, Reginald "Reggie" Montgomery, Kevin Noppinger, and Kelly Riddle  
    • Privacy is Dead - Get Over It - Part 2
    • This will be a wide-ranging lecture covering databases, privacy, and "computer-aided investigation."  Steven is the owner of PallTech, the largest privately held online investigative support service in the U.S.  This talk will include numerous examples of actual data and secret databases as well as a demonstration of an actual online investigation done on a volunteer subject.  During the second hour, Steven will be joined by a four member panel of investigators and intelligence experts.
    • AI Transcript

  52. (2006)  Privacy Through Technology: A Hands-On  - Aldert Hazenberg and Paul Wouters  
    • Until recently, using cryptography to protect your privacy when using the web, email, or instant messenger while connecting your laptop all over the world from very insecure and untrusted networks was a daunting task that most people could never set up.  For those who could, it proved impractical to use over a longer period of time.  Fortunately, things have changed a lot in the last year.  But the notion that cryptography is too difficult to use is still a widespread belief.
    • In this presentation, Aldert and Paul will demonstrate how easy it is these days to use cryptography.  They will bring a Windows and an OSX laptop, and demonstrate how to set up encryption tools from scratch.  After the presentation, a slide show version of their presentation will be available as download for everyone to take home.
    • Topics will include how to secure email using GPG with Thunderbird and Mail.app, how to protect IM traffic using OTR with a variety of IM clients such as Gaim, Adium, iChat, Trillian, or other clients using the OTR proxy, how to encrypt your browsing using Tor and Privoxy, how to build an L2TP VPN to encrypt all your traffic while browsing at Starbucks by using your home DSL, how to encrypt your VoIP calls using Gizmo and Zfone, how to enable WPA/WEP security on your wireless network, and how to use an encrypted hard disk using FileVault or Windows software.  Finally, they hope to be able to show you the first IPsec encrypted Wi-Fi mobile phone.
    • This presentation will be a hands-on training.  That means no slide shows on how things work in theory, but demonstrating live to you that it only takes a few minutes to set up the cryptographic tools to protect your privacy.
    • AI Transcript

  53. (2006)  Proactively Secure Programming Techniques  - Joe Salvatore Testa II  
    • This lecture will teach several proactively secure programming methods that can be applied to direct-memory languages like C and C++.  These methods are an application of the fundamental defense in depth principle that can provide an extra level of security against common buffer overflow attacks, double-free vulnerabilities, and logic errors.
    • AI Transcript

  54. (2006)  Project MF  - Mark Abene (Phiber Optik)
    • This project began in late 2005, when the website www.phonetrips.com came to Mark's attention.  On that site one can find old recordings of phone sounds: call-progress tones, clicks, ker-chunks, all sorts of things.  Someone had traveled around the country back in the 1970s capturing these magical sounds.  In addition, there were a handful of actual recordings of Blue Boxing recorded in a narrated "radio show" format for all posterity.  Hearing those tones brought back memories of when Mark himself experimented with Blue Boxing back in the 1980s.  Blue Boxing can best be defined as directly signaling those legendary MF tones across analog trunks in the old telephone network, exploring the inner workings through pure sound alone.
    • After repeatedly listening to these "phonetrips," Mark thought to himself, "It's a shame all that's gone now.  No more analog trunks or MF signaling, no more 2600 Hz.  SS7 and the completely digital, intelligent routing network are the order of the day."  And that's just the way things are.  But wouldn't it be cool if there was some way to bring it all back?  And so...
    • This presentation is the daring story of how Mark used Asterisk and VoIP to bring back Blue Boxing - essentially a fully working model, connected to the public telephone network, of analog signaling in all its glory.  We can all Blue Box again and Mark will show you how you too, with some Asterisk and VoIP experience, can use his code modifications to Asterisk to set up your very own working analog trunks and vintage routing codes, and ultimately recreate a piece of history for all telecom enthusiasts, MFers, and phone phreaks to enjoy.
    • AI Transcript

  55. (2006)  Pseudonymous Software Development and Strong Distribution  - V. Alex Brennen  
    • A talk and tutorial on cryptographically strong pseudonymous software development and distribution models with the intent being to show hackers that when developing software is forbidden by law, developers can use PGP and other tools to continue to safely exercise their right to free speech in the form of source code.  There will be a description of software release, upgrade cycle, security advisories, development team collaboration, and how to handle the reception of bug reports and patches from users.  In addition you will learn how software developed by cypherpunks like the anonymous re-mailers, onion routing network implementations, and PGP key server networks can be used.  See how the software works in theory (not command line options, etc.) covering topics like public-key cryptography, digital signatures, zero knowledge proofs, and reputation systems.  There will also be a discussion of the use of not commonly used cryptographic technologies such as ring signatures to prevent successful rubber hose attacks by authorities.
    • AI Transcript

  56. (2006)  Radio Communications for Hackers, Amateurs, and Activists  - LinH, Bernie S., Joseph Battaglia, and Skip Arey  
    • Sometimes cell phones, telephone lines, and Internet connectivity just aren't good choices for communications.  Whether those networks are down, unreliable, too expensive, or you just don't trust carriers or ISPs to not hand over all your communications records to Big Brother's data-mining program, there are alternatives.  Amateur (ham) radio, GMRS, FRS, MURS, Part 15, and other technologies can provide free and effective short-range or even global voice/data communications.  This panel will explain how you can use the magic of radio to take control over your communications.
    • AI Transcript

  57. (2006)  Retrocomputing  - Sam Nitzberg, Cheshire Catalyst, Sellam Ismail, and Jason Scott (Jason Sadofsky)  
    • A regular feature of HOPE conferences, this year's retrocomputing panel will reminisce about bulletin board systems.  The dial-up BBS was how many people sent their first email, read forum posts, and found the electronic communities that would later migrate to the Internet.
    • Sellam will also give a brief introduction of the history of computing and talk about the various eras since the invention of the first modern day computers in the 1950s with an introduction to Babbage's work in the 1830s.  Also discussed will be hacker history, phreaking history, how the culture sprang up, and what it has morphed into today.
    • AI Transcript

  58. (2006)  RFID Privacy - Old Threats and New Attacks  - Karsten Nohl  
    • A look at the challenging requirement of anonymity in RFID systems.  After a discussion on proposed solutions to the privacy threat you will see how easily such solutions can be circumvented or completely broken.  By looking at the physical characteristics of the tags, Karsten will demonstrate how new attacks can circumvent these solutions, some of which have been implemented in a lab.  There will then be a look at the back-end infrastructure of the RFID system which will show that the currently outlined implementation will compromise privacy in ways that have never been anticipated - basically allowing for customer tracking over the Internet by everyone.
    • AI Transcript

  59. (2006)  Selfness-Copyfight: From Censorship to New Business Models  - Jorge Cortell, and Alvaro Gonzalez  
    • Pro-copyright cartels use direct extortion, among other methods, to keep their outdated business models and views alive.  Yet the "copyfight" goes on and more and more examples every day prove that their view is not only very shortsighted, but dangerous.  "Selfness" is the extreme opposite of copyright, not only practically (it is currently being used as a business model), but also philosophically.
    • Slides
    • AI Transcript

  60. (2006)  Social Engineering Panel  - Evil Corley and Others  
    • Once again we continue the tradition of not only explaining what social engineering is, but demonstrating it to the throngs as well.  Emmanuel has been confusing people on the telephone for many years and gets a whole lot of pleasure out of tricking total strangers into giving him information he has absolutely no business having.  And after you see this in action, you'll be able to do it too!  We always appreciate suggestions on who can be targeted.  All sorts of special guests may drop by this panel.
    • AI Transcript

  61. (2006)  TrackSploits  - Lance James and Joshua Brashars  
    • In a time where bureaucracy can hold you back against a foe that is more agile, fast, and who definitely doesn't care about the laws they break, a new method of forensics is being developed.  TrackSploits have been used against phishers, malware authors, and distributors as well as "black hat" hackers to gain intelligence on them in a passive, yet active, manner.  These techniques do not break the law, but they will bend them and test the law's resilience.  Techniques include tracking attackers behind proxies, breaking encryption algorithms to unmask IP addresses, stealing data back from the phishers in real-time, and using cross-site attacks to track malware authors.  This talk will open your eyes about intelligence gathering and counterespionage against relentless entities dedicated to causing havoc and profiting from it.
    • AI Transcript

  62. (2006)  Under the Desk at MIT  - V. Alex Brennen  
    • A formal announcement of the creation of the Public Domain Software Foundation (PDSF).  The PDSF is meant to be a parallel to the Free Software Foundation.  It is being started to advocate and support the placement of source code and documentation in the public domain rather than under the GNU licenses.  This presentation will include an explanation of how cryptographic management of identity makes many licenses unnecessary.  Package and patch management solutions are becoming much more automated with Linux distributions as well as with various software packages.  An explanation of why this trend is making the public domain a necessity for many types of modern software.
    • AI Transcript

  63. (2006)  Underground Documentaries: The Art of the Interview and the Access  - Julien McArdle (Seal) and Jason Scott (Jason Sadofsky)  
    • This panel will cover what it takes to make your own underground indy documentary - from asking "attack questions" to recording industry execs to approaching historical legends to sit down with you and be interviewed.  Topics will include the equipment required, legal no-nos, the Creative Commons, editing, distribution, and how to do it all on the cheap.
    • AI Transcript

  64. (2006)  Urban Exploring: Hacking the Physical World  - John and Laura Leita  
    • A continuation of The Fifth HOPE talk that will cover more urban exploring.  Topics will include how to find and navigate university tunnels and how certain aspects of society work/worked by looking through ruins.  This presentation will include pictures and videos of various urban exploration sites.  There will also be a discussion of urban exploring photography, ethics, laws, and safety.
    • AI Transcript

  65. (2006)  Virtual Private Servers and the (Free) Open-Source PBX  - Mark Silverberg (Skram)  
    • Mark will show how VPS virtual server technology can combine with the Asterisk PBX to replace your expensive, proprietary phone system - while still using the same server to run your website!  Not only does this exciting technology apply to old-school Nortel sysadmins (with large corporate budgets) but phreaks at home can try this too!
    • AI Transcript

  66. (2006)  VoIP Unlocking  - The Prophet  (Babu Mengelepouti)  
    • Voice over IP (VoIP) services such as Vonage, AT&T CallVantage, and Packet8 have recently gained popularity.  Unfortunately, there's a catch: your VoIP phone only works with the phone company you bought it from.  In this live demonstration, The Prophet will show you how to free a D-Link DVG-1120M VoIP adapter from the chains of AT&T CallVantage service.  He will also demonstrate FreeWorldDialup, a free alternative to paid VoIP services.
    • AI Transcript

  67. (2006)  Vulnerabilities in a Connected Future  - Sysmin (Nathan Hamiel), and QuiGon (Gene Cronk)  
    • This presentation deals with the vulnerabilities of emerging connected technologies and their uses.  As manufacturers continue to pump out new technology without properly assessing the risks, those risks end up affecting customers.  The focus of this presentation deals with vulnerabilities and attacks on Smarthomes and Smartcars taken from analyzing these emerging technologies.  Vulnerabilities also exist in these technologies from how users interface with and utilize them.  Modern connected technologies are intrusive and it is important that everyone understand the dangers.  This presentation also delivers a healthy dose of problems with the next generation IP protocol, dealing with problems in its implementation and future.  IPv6 will play a big part in the connected future with integration into previously mentioned technologies and mobile devices.  Lastly, the presentation will discuss problems with biometric authentication technologies and refute how these devices are being touted as security silver bullets.
    • AI Transcript

  68. (2006)  Weird Technology  - Gonzo DeMann (Michael J. Ferris), and Leo  
    • This panel will deal with technology that is a bit off the beaten path, technology of the government, private sector, and the home brew variety, as well as the legalities and affects of all this weird tech.
    • AI Transcript

  69. (2006)  Wireless Security Flaws  - Raven Alder, 3ric Johanson, and Brandon Uttech  
    • Wireless security flaws are commonplace but not many people realize just how much of the inner workings of infrastructure and management traffic for large networks are often accessible over wireless.  Working as a team of professional penetration testers, the first time these three saw routing protocols and management traffic visible over 802.11, they thought the client really lacked clue.  The tenth time, it wasn't so funny anymore.
    • This session will show you the common switching, routing, and management traffic commonly present in urban wireless environments, discuss the security risks (from information disclosure to remote exploit), and show you how to prevent this sort of highly critical data from leaving your network by way of your access points.  Using examples from the last five years of growing urban wireless presence, this talk will show the initial signs of backbone control traffic creeping out of poorly secured access points and present statistics on overarching protocol trends over time.  The talk will then take a more serious turn, showing the sorts of damage that a malicious attacker can wreak on a network with the information provided in just a few routing protocol packets.  Lower level attacks such as switching and CDP will also be covered.  Finally, a ray of immediately practical hope will be offered, giving recommendations on actions that will prevent this sort of critical data from being advertised out of your wireless access points.
    • AI Transcript

  70. (2006)  Closing Ceremonies  -
    • The tradition continues.  Instead of going home early, we encourage people to stay late and celebrate the conclusion of the conference.  (Consider Monday a lost day.)  You will hear some of the highlights of the past three days and get one last chance to see people before the next time we decide to do this.  It's also a chance to win all sorts of prizes by demonstrating skills and abilities or just by being at the right place at the wrong time.  And most importantly, you will finally learn who Number One is.
    • AI Transcript



The Last HOPE





  1. (2008)  Advanced Memory Forensics: Releasing the Cold Boot Utilities  - Jacob Appelbaum  
    • This talk will cover some of the issues involved with "Cold Boot" attacks.  A description of the multiple methods (disk, network, etc.) developed for targeting computers whose memory is being targeted for extraction.  The tools used for these experiments will be released here.  In addition, code will be released that was written and has improved since the initial public release of these experiments.  This includes a dumper using a standard iPod with unmodified Apple firmware.  In addition, an improved AES keyfinding tool has been implemented.  Great caution has been taken to not stomp on important bits in memory.  All of the tools will be released as free software.  Possibilities for protection as well as other ideas for improvement of the attacks in software and hardware will be discussed.  The paper related to this talk can be found at http://citp.princeton.edu/memory.
    • AI Transcript

  2. (2008)  The Art of Do-Foo  - Matt Joyce  
    • The one thing that sets a nerd apart from a hacker, a dork, or anyone else for that matter is simple.  Nerds seek to quantify every facet of their lives.  From baseball statistics to Star Trek trivia, there's a little nerd in all of us.  But true nerds pursue the quantification of everything.  The idea of this talk is to quantify successes and failures within the New York City community.  By utilizing modern information theory and simple statistics, we can isolate the key factors that have both positively and negatively influenced the culture in our region.  Why have specific projects succeeded?  Why have others failed?  What are key factors in the success of a community?  This talk will have fun exploring a roller coaster of statistical exploits on what may be one of the coolest and difficult to quantify datasets our planet has ever known.  Learn how to get down with your nerd self in a fun and educational foray into the hacking culture, and the numbers that comprise it.
    • AI Transcript

  3. (2008)  The Attendee Meta-Data Project  - LexIcon, Daravinne, Neo Amsterdam, Aestetix, Echo, Dementia, Matt Joyce, and Christopher Petro  
    • The Attendee Meta-Data (AMD) project is a large scale study of the movement, demographics, participation levels, and interests of HOPE conference attendees over the three day conference period.  At registration, preregistered attendees and others on a first-come first-serve basis will receive a numbered badge with an active RFID chip and a unique PIN.  They will take the badge number and PIN to a terminal, or to the internal website via their own laptop, choose a username, log in, and fill out a web survey querying biographical and interest-based data.  As attendees move around the entire conference area, their presence will be tracked and their movement information will be compiled in a database alongside their contextual data.  All this information will be funneled into a real-time data visualization.  During the conference, attendees will be able to query the database and generate their own visualizations and data comparisons, play games based on timing and location, and find others with similar interests during game sessions.  In this talk, the AMD project development team will discuss the concepts involved and answer questions about the system.  On the last day of the conference during our closing ceremonies, the team will address the project's original goals, the results obtained during the conference, and what was learned throughout the whole process.
    • AI Transcript

  4. (2008)  Autonomously Bypassing VoIP Filters with Asterisk: Let Freedom Ring  - Blake Cornell and Jeremy McNamara  
    • Foreign governments and ISPs within Panama, Belize, the Caribbean, Mexico, Brazil, the UAE, China, India, Saudi Arabia, and others have implemented VoIP filters of some type.  The effect is obvious - phone calls are effectively blocked.  How can Asterisk developers and providers develop mechanisms to help maintain communication through the wake of government supported access control mechanisms?
    • Slides
    • AI Transcript

  5. (2008)  Bagcam - How Did TSA and/or the Airlines Manage to Do That to Your Luggage?  - algormor  
    • Ever wonder exactly how TSA or the airlines managed to destroy your luggage or what security measures are actually in place once your checked luggage disappears from view?  After having yet another bag destroyed while flying several months ago, algormor decided to build Bagcam to find out what happens once the airlines have control of your luggage.  Bagcam is a small suitcase containing a mini-DVR and pinhole camera.  This presentation will cover the construction of Bagcam, potential future enhancements to Bagcam, and issues to consider should you decide to build your own Bagcam.  In addition, various security measures currently in place for commercial passenger flights and the efficacy of these measures will be discussed.  Finally, select footage will be presented from flights through Washington. D.C.'s Reagan National Airport (DCA); Ted Stevens Airport in Anchorage, AK (ANC); Sky Harbor in Phoenix, AZ (PHX); Chicago's O'Hare (ORD); and other airports.
    • Notes
    • AI Transcript

  6. (2008)  Biohacking: An Overview  - Chris Seidel  
    • Biological systems are large assemblies of parts that function together following rules of basic chemistry.  As systems, they can be studied, modified, and engineered for novel purposes.  DNA molecules contain the information used to encode living systems, and methods exist for discovering and manipulating this information.  This talk will cover the basic components of biological systems, including how DNA can be modified to make new proteins or genetically modified organisms, such as fluorescent mice, therapeutic viruses, or bacteria that eat explosives or smell like bananas.
    • AI Transcript

  7. (2008)  Botnet Research, Mitigation and the Law  - Alexander Muentz  
    • This talk will discuss current U.S. federal laws that affect botnet researchers and IT professionals defending against botnets.  Existing methods of capture, analysis, and mitigation will be analyzed from a legal perspective.  Likely scenarios and outcomes will be discussed in an accessible manner.
    • AI Transcript

  8. (2008)  Building a Better Ballot Box  - Smoke  
    • We all know by now the folly of current election technologies from Premier and Sequoia Voting DRE (Direct Record Electronic) systems as well as some of the new, more promising systems on the horizon such as the open-source OVC (Open Voting Consortium) and Scantegrity.  The question of whether we can do better will be raised.  What needs to be done to make this process better than it is today?  Both software and hardware methods to secure the ballot box will be discussed.
    • AI Transcript

  9. (2008)  Building Hacker Spaces Everywhere: Your Excuses are Invalid  - Nick Farr and Friends  
    • Four people can start a sustainable hacker space.  Whether you're in an urban area where space is expensive, in the middle of BFE where finding four people is hard, or just outside of an active war zone in Uganda, there are few excuses left for not joining the global hacker space movement with a place of your own.  This talk will cover the ten most often heard excuses for not building a hacker space and how existing hacker spaces, fab labs, co-working spaces, and other tech-oriented "third spaces" have solved them.
    • AI Transcript

  10. (2008)  Citizen Engineer: Consumer Electronics Hacking and Open-Source Hardware  - Phillip Torrone and Limor Fried  
    • In addition to the future of DIY, building hardware, open-source hardware, and a roundup of amazing projects anyone can build, this talk will present the debut of the film Citizen Engineer - named after the HOPE Number Six talk.  The session will be the first time this how-to video series for hacking is shown in public.  There will also be some hands on hardware demos, hacking, and a lot of trouble.
    • Adafruit: Citizen Engineer
    • AI Transcript

  11. (2008)  A Collaborative Approach to Hardware Hacking: NYCResistor  - Bre Pettis and Friends  
    • In this panel, 18 members of NYCResistor will each, in turn, speak about a piece of infrastructure or project associated with their hacker space collective.  By presenting 18 perspectives on the infrastructure, process, and projects, you will experience different windows into the organization.  The presentation will encompass stories and pictures of cake, lasers, and drink serving robots as well as insight into such fascinating topics as book balancing, documentation, and the massive importance of failure.  NYCResistor is a Brooklyn-based hacker space focused on learning, sharing, and making things.
    • AI Transcript

  12. (2008)  Community Fabrication  - Far McKon (Jon McKamey)  
    • In the 1970s, computers were still the foray of big business and government.  They were known to be powerful tools, but they were beyond the reach of individuals.  Though several other home computers came out in the early 1970s, the MITS Altair 8800 is generally credited as sparking the home computer revolution, which in turn sparked computers everywhere.  The base of another revolution in fabrication powered by hobbyists will be revealed here.  The Fab@home, RepRap, and other projects will (hopefully) do the same thing for fabrication.  This talk will cover community based fabrication, why it's so cool, and how it could fundamentally alter the global economy for the better.
    • AI Transcript

  13. (2008)  A Convergence of Communities  - John Strauchs  
    • Most people in either industry already know something about the relatively recent convergence of computer technology (CT) and physical security.  But they probably aren't aware that computer professionals are increasingly assuming a leadership role in the process, as well as the management of the process.  Moreover, the physical security and computer technology (CT) and information technology (IT) communities have traditionally been at odds.  Computer professionals don't know as much about physical security electronic systems and devices as they think they do.  Conversely, physical security senior managers know virtually nothing about CT and some don't want to!  This session will examine the convergence phenomenon from both perspectives.  It will review what is occurring, how it is happening, and what effects it has on both security and CT/IT.  The effects upon, and from, the Department of Homeland Security will be discussed.  The session will conclude with an in-depth analysis of Homeland Security's shortcomings and unmet needs and the role of CT/IT in protecting the nation.  The critical need to triage security resources will be examined, along with a look at how it should be done, as well as an attempt to understand why it isn't already happening.
    • AI Transcript

  14. (2008)  Crippling Crypto: The Debian OpenSSL Debacle  - Jacob Appelbaum, Dino Dai Zovi, and Karsten Nohl  
    • In May 2008, a weakness in Debian was discovered which makes cryptographic keys predictable.  A Debian-specific patch to OpenSSL broke the pseudo-random number generator two years ago, which led to guessable SSL and SSH keys.  The vulnerability allows for impersonation of secure servers, as well as the potential to login to SSH secured systems.  Since many popular derivatives like Ubuntu and Xandros are affected, the weak keys are found all over the Internet.  The panel will present their approach to generating lists of weak keys using cloud computing and explain how they collected large numbers of SSL certificates of which several thousand are weak.
    • AI Transcript

  15. (2008)  Death Star Threat Modeling  - Kevin Williams
    • In the field of Information Security, the terms vulnerability, threat, and risk have specific meanings and are often misapplied and misidentified in projects.  This presentation will explain threat modeling as it applies to information and application security projects, utilizing the shared memory of the Death Star trench run as an analogy to better understand these concepts.  You will learn how to define risks, threats, vulnerabilities, and countermeasures; how to integrate threat modeling into a software development lifecycle; examine example threat modeling methodologies; and hear real-world anecdotes of threat modeling successes and failures.
    • AI Transcript

  16. (2008)  A Decade Under the DMCA  - Marcia Wilbur  
    • In October 1998, the Digital Millennium Copyright Act (DMCA) was signed by President Clinton.  Since that time, the DMCA was used to prevent free speech and reverse engineering.  The DMCA offers patent-like protection although this is a copyright law.  Many people have been adversely affected by the DMCA.  Cases will be discussed and information regarding filing counter notifications will be presented.
    • AI Transcript

  17. (2008)  Dirty New Media: Art, Activism, and Computer Counter-Cultures  - Jake Elliott  
    • This talk presents a short history of electronic art by illustrating connections between artists, activists, and hackers.  The connections and histories presented include: the demoscene and its origins in software piracy; video and conceptual artists in the 1970s and their activist work; contemporary artists working with circuit bending and other detournements of modern technologies; the Chicago "dirty new media" community; contemporary artists, hackers, and activists creating software and electronic art with a punk/anticapitalist ethos.  Excerpts of work from these different artists and communities will be screened and discussed.
    • AI Transcript

  18. (2008)  Earth Intelligence Network: World Brain as EarthGame  - Robert Steele
    • The first speaker at the first HOPE in 1994 will describe the emergence of the Earth Intelligence Network, the World Brain, and EarthGame as the triumvirate that will empower We the People and make most governance and many organizations both transparent and obsolete.  Emphasis will be placed on the eradication of corruption and restoration of the sovereign individual.
    • AI Transcript

  19. (2008)  E-Mail: Descendant of the Telegram  - The Cheshire Catalyst
    • The former Telex hacker will take us on a verbal tour of yesteryear when telegrams meant the smell of machine oil and teletype machines.  You'll learn how the term "break text" became the equal sign and why you should indent your name five spaces to "sign" your e-mail.  It's a geek thing.  Maybe you can understand.
    • AI Transcript

  20. (2008)  The Emperor is Naked - Virtualization Technolgies Examined  - Michael Kemp  
    • Virtualized technologies are being lapped up left, right, and center by corporates committed to the cash savings they promise.  Sadly, the savings that can be gleaned are not without the attendant risk.  Instead of nice normal networks that people can understand, many vendors are offering networks in a box.  As well as being lovely single points of failure, they have a number of risks that remain largely unexplored.  Research has already been conducted around platform virtualization technologies such as VMWare, but there still exists a fundamental flaw within virtualized resource technologies that no one seems to have spotted.  This talk will illustrate why and how virtualization works, what the difference is between what the vendors say and how it is being implemented in RL, and will discuss a theoretical vulnerability that if it can be exploited can bring down the house of cards.
    • AI Transcript

  21. (2008)  Escaping High Security Handcuffs  - Ray  
    • Everybody knows normal police handcuffs are no real challenge for lockpickers, even though it helps to know the inner workings and tiny differences of the various models in use today.  Less publicly known is that there's also a variety of "high security" handcuffs on the market, used mainly for high-risk prisoners and during transfers.  But those also have their weaknesses...  This talk will give an overview of the products in use today and their different attack vectors - not only focusing on picking but also bypassing some of the most advanced locking mechanisms used in this field.
    • AI Transcript

  22. (2008)  Evil Interfaces: Violating the User  - Gregory Conti  
    • In a perfect world, interfaces help users accomplish tasks quickly and efficiently.  However, in the real world, interfaces are often designed to manipulate users into behaving according to the designer's calculated and suspect intent.  Malicious interfaces abound on the web - employing trickery, misdirection of browsing, forced viewing of advertisements, and even animations designed to trigger epileptic seizures.  Evil interfaces are seen virtually anywhere profit is at stake, from desktop applications and websites to gas pumps and toothpaste dispensers.  This talk explores malicious interface techniques both on and off the desktop, and aims to energize the audience to pursue positive solutions.  You'll leave with a better awareness and understanding of the problem, increased resistance to attack and ideas for generating solutions.
    • Slides
    • AI Transcript

  23. (2008)  Exploration of Possibilities: Brain Hacking  - Dot.Ret  
    • The human brain is an incredibly complex and advanced central processing system.  Interestingly enough, in spite of its uniqueness in several respects, it has many qualities in common with modern computer systems.  Like modern computer systems, the brain and ultimately the mind can be predictably influenced and even exploited.  This talk will cover the basic nature of the brain in relation to computer systems and will discuss the relevance, the advantages, and the dangerous implications of this topic.
    • AI Transcript

  24. (2008)  Jello Biafra Keynote  - Jello Biafra (Eric Reed Boucher)
    • A regular speaker at HOPE since 2000, Jello provides a unique and charismatic look at what's been going on in the world since the last time we all got together.  Whether you're a technologist or a technophobe, his words will almost certainly have an effect on your emotions one way or another.
    • AI Transcript

  25. (2008)  Kevin Mitnick Keynote  - Kevin Mitnick  
    • The "world's most dangerous hacker" and subject of our documentary Freedom Downtime ($30) (along with many other more sensationalist pieces over the decades) gives us an update on what's been going on in his life since the last time he was here in 2004.  (A severe case of food poisoning in Colombia forced him to cancel his HOPE Number Six appearance - which may be one of the stories he tells this time.)
    • How to Unmask Caller-ID Using Asterisk  
    • AI Transcript

  26. (2008)  Steven Rambam Keynote - Part 1  - Steven Rambam (Steven Rombom)  
    • Steven Rambam Keynote - Part 2
    • Hopefully there will be no surprises this year.  In 2006, privacy expert Steven Rambam's two hour panel was disrupted by federal authorities who arrested him at the conference just prior to its commencement.  In the end, he was completely vindicated and went on to finally give his talk several months later to a packed house at a local university.  This year, Steven will be on for three hours, in part to make up for what you may have missed last time, but mostly because what he says about the state of privacy in our society will captivate you.
    • AI Transcript

  27. (2008)  Adam Savage Keynote  - Adam Savage  
    • The esteemed co-host of the popular TV show Mythbusters on the Discovery Channel and "a maker of things" will give a captivating talk on the nature of his particular obsessions.
    • Post-Talk Interview  (3.5M MP3)
    • AI Transcript

  28. (2008)  From a Black Hat to a Black Suit - How to Climb the Corporate Security Ladder Without Losing Your Soul  - Myrcurial (Dave Lewis)  
    • You want it all.  You can see the brass ring and you want to jump for it.  But you're scared.  You don't want to put on a suit and watch your soul shrivel like the spot price on RAM.  There is another way.  In this session, you will learn: why you want to do this to yourself, how to get the first job (which will suck), how to turn the first job into the next job (while still having fun), how to get the top job (sooner than you thought you could), and how to do it all without feeling like a corporate whore.  You want to hack the planet?  You've got to start somewhere.
    • AI Transcript

  29. (2008)  Ghetto IDS and Honeypots for the Home User  - Black Ratchet (Ben Jackson)  
    • Have you ever wondered what the heck was pounding on your Internet connection?  Or what exactly was making your cable or DSL connection's activity light blink wildly when you knew there was no traffic from you?  If so, this presentation will shine a light into the dark corners of your personal tube, showing you the unending stream of junk that comes across your Internet connection as well as how to pick out the good, the bad, and the ugly.  This presentation will cover the steps involved in setting up a poor man's IDS and honeypot.  Using open and freely available tools, strategies of IDS deployment on your home LAN and the setup of both low interaction and high interaction honeypots will be covered.  Learn what you can expect to see, how to pluck out the signal from the noise, and generally be aware of what is flowing in - and out - of your LAN.
    • AI Transcript

  30. (2008)  Graffiti Research Lab Extravaganza  - Graffiti Research Lab  
    • GRL's presence at HOPE this year will be represented by Graffiti Research Lab in Utah.  Michael Auger (a.k.a. Love Monkey 4000) will come from the mountains of Utah to the Big Apple to run workshops, conduct technology demonstrations, screen a movie, and announce (for the first time) a new GRL project very close to his heart: One Laser Tag Per Child.  The event will start with a LED Throwie workshop.  Throwie workshops only last until the supplies run out, anywhere from 30 minutes to an hour.  The screening of the new GRL movie (fresh from Sundance, MoMA, the Tate Modern, etc.): Graffiti Research Lab: The Complete First Season will then begin.  People will be encouraged to misbehave with their throwies in the dark, yell at the screen, etc.  All this will be documented so that the HOPE viewing of The Complete First Season will actually be footage for the sequel: Graffiti Research Lab: The Complete First Season II.  After the movie ends, GRL Utah will come to the front of the room and introduce GRL live via webcam from Korea.  New GRL technologies and initiatives will be unveiled, including (but not necessarily limited to) the One Laser Tag Per Child system.  During the course of the HOPE conference GRL Utah will man a table where interested attendees will be able to do the following: play with lasers, get trained on how to set up the laser tag system, take a closer look at the prerelease of the One Laser Tag Per Child system, download the disc image of the GRL movie (or buy the actual DVD), learn how to set up a GRL in their hometown.
    • AI Transcript

  31. (2008)  Grand Theft Lazlow - Hacking the Media by Laughing at Them  - Lazlow Jones  
    • A talk by Grand Theft Auto IV cowriter and coproducer Lazlow focusing on that phenomenal project as well as what's been going on in media in the last decade.  Beginning in 1996, corporations began gobbling up every newspaper, billboard, radio and TV station in the United States.  Ironically, since then, readership and ratings have plummeted, resulting in entertainment executives and editors programming even more sensationalist and desperate content.  Lazlow discusses how parody of the media in video games, on TV, and online can often garner a larger audience reaction than the media establishment itself.  He will describe why the mainstream media invents crises, and the reaction by the media and Hollywood establishment to the growing popularity of interactive worlds where players are celebrities rather than smug starlets tittering for TMZ.  How can you hack the media?  In this interactive talk Lazlow talks about his work in radio, video games, and the future of the media, democracy, and the role of comedy in it.
    • AI Transcript

  32. (2008)  Hackateer Premiere  - John Threat (John Lee) and Mark Abene (Phiber Optik)  
    • Hackateer is an episodic adventure series about a team of hackers who are being chased by quasi-government agencies.  The show blends a reality "Do-It-Yourself" tech show with a scripted spy/adventure narrative shot in anime style.  Embedded within the entertainment of an episode, viewers learn how to take everyday technology and use it in ways they never dreamed of and not always originally intended.  The show also features interrogations with top hackers and tech people from around the world that are kidnapped by the Hackateers.  Hackateer is also unique in that the show is cast with real underground hackers and the stories are drawn from world famous hackers and their real life exploits.
    • Hackateer Trailer  Season 1
    • Hackateer Guide
    • Memory Thieves Teaser
    • AI Transcript

  33. (2008)  A Hacker's View of the Freedom of Information Act (FOIA)  - Phil Lapsley  
  34. (2008)  Hacker Space Design Patterns  - Jens Ohlig
    • How do you get a hacker space started?  How do you manage it once you have a space?  This talk presents wisdom collected over a decade of building sustainable hacker spaces in Germany.  Through "design patterns," Jens and Pylon will cover the essentials of assembling an initial group, finding the perfect location, and managing the community.  Earlier versions of this talk have inspired the creation of the U.S. hacker spaces NYCResistor and HacDC.  This version will inspire and help you create a hacker space where you live!
    • AI Transcript

  35. (2008)  Hackers and Planet Earth  - Peter Jackson
    • Technological innovations of the last few centuries have changed our relationship with Planet Earth.  With fossil fuel supplies in decline, energy demand growing, and worrying climate change predictions, the future doesn't look great.  The presentation will start by briefly looking at the challenges that lie ahead.  What can we as hackers, both individually and collectively, do to be more environmentally sustainable?  How could we use our skills in the event of the situation reaching crisis point?
    • AI Transcript

  36. (2008)  Hacking Cool Things with Microcontrollers  - Mitch Altman  
    • Microcontrollers can do your bidding.  This presentation will show a few fun, simple projects that Mitch has hacked together as examples to show how fun and easy it is to create your own microcontroller projects - even for people who have never built anything in their lives.  Sample projects include: The Brain Machine, TV-B-Gone, Trippy RGB Light, LED Cube, Solar BugBot, and Mignonette (a very simple handheld game platform).  Basic hardware design, simple firmware design, and how to use the free, open-source software available for programming the chips used will be discussed at this talk.
    • AI Transcript

  37. (2008)  Hacking Democracy: An In Depth Analysis of the ES&S Voting Systems  - Matt Blaze, Sandy Clark (Mouse), Eric Cronin, Gaurav Shah, Micah Sherr, Adam Aviv, and Pavol Cerny  
    • Last Fall, Ohio Secretary of State Jennifer Brunner commissioned Project EVEREST, a comprehensive security review of the electronic voting technology used in her state.  The project contracted several academic teams and others to examine the election procedures, equipment, and source code used in that state, with the aim of identifying any problems that might render elections vulnerable to tampering under operational conditions.  The ten-week project examined in detail the touch-screen, optical scan, and election management technology from e-voting vendors ES&S, Hart InterCivic, and Premier Election Systems (formerly Diebold).  Penn led the analysis of the ES&S system source code, which is also used by voters in 42 other U.S. states besides Ohio.  This talk will outline the U. Penn team's findings, which included the discovery of exploitable security vulnerabilities in almost every hardware and software component of the ES&S touch-screen and optical scan systems.  Some of these flaws could allow a single malicious voter or poll worker to alter countywide election results, possibly without detection.  The team will discuss their findings and will also describe more generally the process of analyzing 700,000 lines of unfamiliar source code in less than ten weeks under highly constrained conditions.  The full 334 page report (which also includes analysis of the Hart and Premier systems done at Penn State and WebWise Security) can be downloaded from the Ohio Secretary of State's web site.
    • Academic Evaluation and Validation of Election-Related Equipment, Standard and Testing - Final Report  (11.6M PDF)
    • AI Transcript

  38. (2008)  Hacking International Networks and System(s) using VoIP  - Da Beave (Champ Clark) and Jfalcon  
    • There is an entire world of PSTNs out there that most people never bother to look into.  People have a tendency to call within their area (country) and never stray or "wander" outside.  This talk hopes to change that perception.  With VoIP, we have the ability to call worldwide for fractions of a penny.  Why not call that X.25 network in Russia?  Or India?  Why not explore foreign data networks and find new and old things still out there?  Think war dialing in the U.S. is washed up?  Why not try a country where computers and technology are built on the hardware we've thrown out?  In many parts of the world, phone networks and data networks are built using the existing PSTN infrastructure.  They simply can't afford to purchase modern SONET/DS hardware.  Nor can they afford to run fiber optics or coax to every neighborhood.  The legal ramifications in hacking such systems are significantly less than hacking U.S. computer networks.  The media is filled with reports of Chinese hackers infiltrating U.S. networks.  That being said, doesn't it make sense to return the favor?
    • AI Transcript

  39. (2008)  Hacking the Mind, Hacking the Body: Pleasure - Part 1  - C4bl3FL4m3  
    • Hacking the Mind, Hacking the Body: Pleasure - Part 2
    • A continuation of the infamous "hacking sex" third track presentation from HOPE Number Six.  This will be a talk about sexuality, pleasure, and our bodies from a hacker's point of view covering such diverse methods as hypnosis, BDSM, role play, sex toys, and body modification.  C4bl3FL4m3 will share her in depth (and sometimes hands-on) knowledge in increasing the pleasure felt by ourselves and our partners.  With brand new material as well as tried-and-true secrets, this presentation is perfect for all genders and orientations.  Topics covered will include erotic hypnosis, sex toys and their usage, BDSM, body modifications, meditation and other sexual/spiritual forms of mind altering, sexual role play, sexual techniques, cybersexuality, tele and technodildonics.
    • Notes
    • AI Transcript

  40. (2008)  Hacking the Price of Food: An Urban Farming Renaissance  - Bicycle Mark (Mark Fonseca Rendeiro)  
    • With the global price of food rising dramatically around the world, the number of people at risk of starvation and malnutrition will also increase.  The United Nations Food Program announced earlier this year that it would not have enough money or food to meet its targets due to the cost of food.  In Egypt and other parts of the world, people have been rioting in the face of food shortages and sharp increases in prices.  In places like Thailand that are famous for exporting rice throughout the world, the government has announced cutbacks in exports because of shortages.  A grim picture, to say the least.  Yet while this crisis seems to be unfolding, another rise has come to pass - the return of urban and community farms.  How do these farms manage to exist, seemingly, outside the global game?  Is their business model sustainable and is this truly a renaissance of growing and thinking locally?  Through a series of podcast interviews and reports, the case is presented of how some farmers are hacking the price of food.
    • AI Transcript

  41. (2008)  Hacking the Young Lady's Illustrated Primer: Dispatches from the Field of Educational Technology  - Gillian "Gus" Andrews, and Ivan Krstic  
    • The takeaway message of this panel will be that the critical element in teaching with technology is people - and that hackers need to consider what this means.  The talk will encourage the audience to consider the best ways to tackle the horrendous failures of current technology education.  Topics to be covered: Neal Stephenson's The Diamond Age/Young Lady's Illustrated Primer and whether it can be achieved; the one laptop per child project and the difficulties it currently faces; hair-raising experiences writing an A+ certification curriculum; whether the Pacific Northwest Tree Octopus is real; responses from seventh-graders (or Why Johnny Can't Read on the Internet); and Richard Feynman already taught us everything we needed to know about education - why aren't we listening?
    • AI Transcript

  42. (2008)  The History of Phone Phreaking, 1960-1980  - Phil Lapsley  
    • This talk will give a brief history of phone phreaking from 1960 to 1980 the Golden Age of the analog telephone network.  After a quick introduction to the then-modern long distance network and "operator toll dialing," you'll see how the first "Blue Box" came to be, look at why organized crime loved the technology, and see how AT&T and the Department of Justice reacted to this fad in the 1960s.  You'll then follow the phreaks into the 1970s as their hobby hit the mainstream in 1971 with the publication of Secrets of the Little Blue Box in Esquire and the founding of YIPL, the first phone phreak newsletter.  As a bonus, you'll get to listen to some sounds of the old network!  If you've ever used a Blue Box, this will be a phun trip down Memory Lane - and if you haven't, you'll get to listen to some great examples of hacking with tones!
    • AI Transcript

  43. (2008)  Home is Where The Heart Is?  The Question of Jurisdiction  - Douglas Spink  
    • A presentation on the subject of corporate legal jurisdictions and related topics.  While this sounds boring on the surface, it's actually not - and is more and more relevant every year for those in the tech game.  As physical human beings, we do in fact have a "home jurisdiction" in the legal sense, which is wherever we are living at present.  However, corporations are also "people" in the legal sense but have a flexibility of where they call home.  This ties into areas of international legal issues, corporate governance, privacy of company information, financial systems/banking, personal versus corporate liability, and so on.  Basically, for anyone from a coder who wants "a company" to bill his clients through, all the way up to major tech projects that span multiple jurisdictions in a sophisticated way, few of us who play the tech game are not directly impacted by the question of where a company lives, where it calls home.
    • AI Transcript

  44. (2008)  How Do I Pwn Thee?  Let Me Count The Ways  - RenderMan (Brad Haines)  
    • The business world has spawned a new kind of creature, the mobile, traveling worker.  This creature typically carries a multitude of wireless devices on them while traveling to and from clients.  Unless special care has been taken, these devices present a plethora of ways to pwn them and their data.  This talk will take a look at a worst case scenario and go through all the ways one of these business travelers can be pwn'd at a distance by a bored attacker in an airport, hotel, or other public space.
    • AI Transcript

  45. (2008)  How Piracy Feeds a Starving Audience  - Michael Perkins
    • This talk will present observations of the relationship between technology and art in a comprehensive look at how the rise of piracy and its effect on the music industry can enrich the art form as well as the global audience.  Drawing from the ideology of open-source and user-supported technology, this talk will attempt to demonstrate that the concept of "free music" is set to overhaul the way in which music is created and acquired.  The topics to be discussed include the history of the music industry, the war with the RIAA, Digital Rights Management, Creative Commons, and more.
    • AI Transcript

  46. (2008)  How to Talk to the Mainstream Media  - Stephen Cass  
    • Why bother with the mainstream media?  Because that's where the audience is.  Only a tiny percentage of blogs have sizable audiences and even the biggest of those are dwarfed by the audiences for TV news or the circulations of the larger dead-tree newspapers and magazines.  Even online, websites run by mainstream media organizations are major players.  If you're interested in getting your point across to as many people as possible, this talk will improve your chances by telling you what professional journalists want and why, how you can help give it to them, and what pitfalls to avoid.  Also: how to become a TV pundit!
    • AI Transcript

  47. (2008)  Identification Card Security: Past, Present, Future  - Doug Farre  
    • Come learn how identification cards have taken over our lives, how they can be manufactured at home, and how you can start a legal ID making business.  Learn all the tips and tricks about amateur ID manufacturing and pick up the first ever Complete Amateur ID Making Guide.  Also, come test your ability to spot a fake versus a real and check out the newest in ID technology: polycarbonate laminates, biometrics, Teslin, and RFID.  Lastly, see how corporations are affecting the identification card fiasco in the U.S. and how the Real ID Act is going to affect you.  What's in your wallet?
    • AI Transcript

  48. (2008)  The (Im)possibility of Hardware Obfuscation  - Karsten Nohl  
    • This talk will discuss several different approaches to reverse engineering proprietary algorithms from hardware.  It will focus on our mostly automated approach to reconstructing functionality by using a combination of analyzing photos of chip structures and protocol analysis.  Using these techniques, the Mifare RFID tags were hacked, which caused quite a bit of public discussion about proprietary cryptography and "security by obscurity."  The cryptography of the Mifare tags has several vulnerabilities including weaknesses in the random number generator and low resistance against brute-force attacks.  Furthermore, statistical flaws of the cipher enable very practical key-recovering attacks.  This presentation will show the whole range of attacks as well as some general techniques to improve cryptographic protocols so they are more resistant.
    • Notes
    • Slides
    • HOPE 2008: The Impossibility of Hardware Obfuscation  Hack a Day entry.
    • AI Transcript

  49. (2008)  The Innermost Unifier: Today It's the Corporate Anthem  - Johannes Grenzfurthner
    • Using different historical and current examples (especially from the area of the hardware/software-industry), Johannes will give a theoretical and applied - and not unamusing - overview on the musical genre of corporate anthems.  Come and sing along.  Powernapping is welcome, too.
    • AI Transcript

  50. (2008)  Installation Art in HOPE Space  - Daravinne (Christina Olson), Albert Hwang (Phedhex), Randy Polumbo, Erik Sanner, and Sean Mongomery
    • In an effort to continue the knitting together of the art scene and the tech scene, Daravinne has gathered local artists to create art installations in the lobby and mezzanine spaces of the conference.  Four artists are being showcased, each with their own unique spin on tech art.  Albert Hwang has created a 3D wiremap, Randy Polumbo has some electrified flowers, Erik Sanner wants us to play chess, and Sean Montgomery's biofeedback wearables will tell you how you're feeling.
    • AI Transcript

  51. (2008)  The Intersection of Culture Jamming, Hacking, and Hacktivism - Part 1  - Pan Goat (Jaime Magiera), Phineas Narco, Tim Maloney, %20, Fred Church, Steev Hise, Ricardo Dominguez, Bernardo Attias, and Mark Hosler
    • The Intersection of Culture Jamming, Hacking, and Hacktivism - Part 2
    • Over the past nearly 20 years, the Internet has proved to be fertile ground for projects that raise awareness, question authority, and inspire social cohesion.  Culture jamming, hacking, and hacktivism have helped provoke changes in the technical, cultural, and political aspects of our society.  This panel aims to provide an overview of these techniques through examples of some of the more memorable projects.  Starting with the manipulation of voicemail services and leading up to denial of service attacks on government web servers, the panel will cover how these projects were organized and executed as well as the reaction that they inspired.  This 90 minute panel will also include a discussion section (with audience participation encouraged) where they will contemplate what use these techniques have in light of the quickly changing Internet and digital media landscapes.
    • AI Transcript

  52. (2008)  Introduction to MCU Firmware Analysis and Modification with MSP430static  - Travis Goodspeed
    • The Texas Instruments MSP430 is a low-power, 16-bit microcontroller which is rapidly gaining in popularity in the embedded world.  MSP430static is a tool for reverse engineering the MSP430's firmware.  Following a quick tour under the hood of this tool, this lecture will demonstrate how to analyze, modify, and reflash a black-box firmware image.
    • AI Transcript

  53. (2008)  Introduction to the Open Web Application Security Project  - Tom Brennan (jinxpuppy)
    • This talk will provide attendees with an introduction to the Open Web Application Security Project as well as a discussion and demo of application security hacks based on research of common client issues discovered when performing assessments.  In the end, those attending will have a better understanding of APPSEC.
    • AI Transcript

  54. (2008)  IPv6, the Next Generation Network Playground - How to Connect and Explore  - Joe Klein
    • A replacement for IPv4 was first imagined after the 1990 report warning of IP address exhaustion was released.  It took another five years until the RFC for IPv6 was released and another year before it was implemented in an operating system (BSD) and a network (6BONE).  During that time RFCs meant to extend the useful life of IPv4 were killing the end-to-end connections.  This includes RFC 1518 - Classless Inter-Domain Routing (CIDR), RFC 1631 - Network Address Translation (NAT), and RFC 1918 - Address Allocation for Private Internets.  From that point on, many protocols required workarounds, patches, and hacks just to continue to communicate.  Worse yet, each change reduced the usefulness of firewall and increased the attack surface.  Now, 18 years later, we have the opportunity to test and explore this replacement for IPv4.  This presentation will discuss the basics of IPv6 including features, benefits, and addressing.  There will also be a review of how to connect to the IPv6 network - even if your ISP is clueless.  Discussion will include a review of tools needed to test and explore IPv6 as well as a look at the most common IPv6 vulnerabilities.
    • Slides
    • AI Transcript

  55. (2008)  Steven Levy Keynote  - Steven Levy  
  56. (2008)  Kitchen Hack Lab: Interactive Food Disassembly  - Gweeds (Guido Sanchez)  
    • Open-source recipe development vs. secret restaurant techniques, hacked hardware vs. expensive science toys.  Food hacking is the redheaded stepchild of molecular gastronomy.  With audience participation, there will be some weird cooking, documenting of tasting notes on the wiki, a demonstration of current culinary exploits with kitchen appliance hacks, and an introduction of some recent food hacking ventures including hack lab tours and some dope culinary software.
    • AI Transcript

  57. (2008)  Macro Social Engineering  - LexIcon
    • Macro social engineering is using social interactions, mass media, and other methods to affect wide scale social change.  LexIcon will talk about leadership and the artist's editorial voice in relation to his own efforts to improve both the hacker community and the global community.
    • AI Transcript

  58. (2008)  Maintaining a Locksporting Organization and Breakthroughs in the Community  - Doug Farre and Jon King  
    • This presentation will go into detail about how to start and maintain a locksport organization and how groups like these can lead to influential research.  You'll learn how to keep everyone excited about lockpicking and how to turn your club into a well oiled machine for years to come.  In addition, you'll find out what it takes to produce a good lockpicker and see how anyone can influence the lock industry even after only a few months of being on the scene.  Jon King's research on high security Medeco locks will be revealed in detail.  There will also be a demonstration on how to build a tool to pick high security cylinders, and how the responsible disclosure of exploits in the hardware world can make a positive impact for all involved.
    • AI Transcript

  59. (2008)  Methods of Copying High Security Keys  - Barry Wels and Han Fey  
    • In this two hour workshop you will learn some new and advanced opening techniques for high security locks from two key members of the locksport group TOOOL in the Netherlands.  Special attention will be given to duplicating high security keys and detailed analysis of modern locking systems.  After the presentation, some of the tools and techniques can be seen up close at the Lockpicking Village.  You are invited to bring your complex locks or "impossible to copy" keys....
    • AI Transcript

  60. (2008)  Monumental Women Who Influenced Today's Technology  - L33tphreak
    • An historical summary of females who either participated in or were pioneers of advancements that affect the technology-driven industries of today.  This talk will be covering topics including: the gender bias surrounding ENIAC and how it pushed women to show they can succeed in a "man's world," how "The Women of ENIAC" came to be and why, historical females in computing sorted in chronological order by birth starting in the early 1800s, the women who contributed to telephony, and ending with a short video clip borrowed from Nightline.  This is designed as a 50-minute whirlwind journey exposing the estrogen-laced side of technology - women are strongly encouraged to attend and show their pride of being female geeks (a rare find in the testosterone ocean of technology).
    • AI Transcript

  61. (2008)  The New York City Taxi System: Privacy vs. Utility  - Nick Leghorn  
    • When people think of New York City, three icons come to mind: the Statue of Liberty, the Empire State Building, and the classic yellow taxi cab.  However, even the most seasoned New Yorker barely understands the complicated system that transports over 241 million passengers every year, includes more than 40,000 vehicles, and generates in excess of $2 billion every year.  During this presentation you will learn about the New York City taxi system and how the new technologies (such as GPS tracking, credit card transactions, SMS messaging, and touch screen kiosks in the car) are being implemented, including the privacy and security concerns that surround them.  You'll also take a peek at some of the proposed changes that will make the New York City taxi system more accessible and more efficient.
    • AI Transcript

  62. (2008)  No-Tech Hacking  - Johnny Long  
    • The best way to describe this talk is to simply quote some of what we received from its presenter:
    • "I'm Johnny.  I hack stuff.  I've been at it for quite a while now, and I've picked up a few tricks along the way.  I get asked about my tricks all the time, mostly by kids who saw that movie.  You know the one.  But I've always said no.  I've held onto my secrets as part of the pact I made with the hacker underground.  I mean, I'm allowed to give talks and presentations about hacking stuff, but the secrets... the real super-cool secrets I've had to keep to myself.  The head of the underground said so.  But I got this email the other day that says I'm THIS close to getting kicked out of the underground.  Seems the glare of the public eye has been on me for far too long and I've become a liability.  So, I'm going to be proactive.  I'm going to quit before they can fire me....  The underground is gonna be sooo ticked off."
    • AI Transcript

  63. (2008)  "Off the Grid" Voice & Data Communications  - Skip Arey, Bernie S., Redbird (Joseph Battaglia), and LinH  
    • It's Orwellian.  We're so conditioned to believe we've little choice but to rely on government-regulated, corporate-owned voice/data networks designed to log our communications traffic and content.  People can be held incommunicado by routine network failures, natural disasters, and by political actions- often when communications is needed most.  But modern two-way radio can provide effective and reliable short-range and global voice/data communications at relatively little cost, and it can't be logged by conventional (CALEA) methods.  This discussion will tune into the latest surprising developments in amateur (ham) radio, unlicensed spread-spectrum, and other two-way radio technologies and applications.
    • AI Transcript

  64. (2008)  One Last Time: The Hack/Phreak History Primer  - Jason Scott (Jason Sadofsky)  
    • In 2008 $2600 is 24-years-old, the computer bulletin board system is a 30 year relic, and a good number of attendees of HOPE were not born when some events of the "modern" era of computers and hacking began.  Historian Jason Scott of textfiles.com presents a quick primer of a large part of the basics of hacking and phreaking history, touching on those sometimes obscure or hilarious subjects that may have escaped notice in a Web 2.0 world.
    • AI Transcript

  65. (2008)  Packing and the Friendly Skies - Why Transporting Firearms May Be the Best Way to Safeguard Your Tech When You Fly  - Deviant Ollam
    • After a particularly horrible episode of airport theft, Deviant made the decision to never again travel by air with unlocked luggage.  Because of this he now flies with firearms all the time.  Federal law allows (in fact, it requires) passengers to lock firearm-bearing luggage with non-TSA-approved padlocks and does not permit any airport staffer to open such bags once they have left the owner's possession.  In this talk, you will learn the relevant laws and policies concerning travel with weapons.  It's easier than you think, often adds little to no extra time to your schedule (indeed, it can expedite the check-in process sometimes), and may actually be the best way to prevent tampering and theft of bags during air travel.
    • Slides
    • AI Transcript

  66. (2008)  Pen-Testing the Web with Firefox  - John "DaKahuna" Fulmer and Michael "theprez98" Schearer  
    • Hacking the web has never been easier.  Whether you're using Firefox as a standalone tool for information gathering, modifying your browser with innovative extensions, or using Firefox as a web front-end for other penetration testing tools, you can hack all within the potentially anonymous cozy confines of your customized browser.  Putting it all together brings your hack-foo one step further.  DNS lookups, uptime reports, hosted hash crackers and online scanners are at your browser's fingertips.  With Firefox's innovative add-on feature, a number of powerful extensions have been developed for security scanning, ethical hacking, penetration testing, and general security auditing.  Finally, a number of penetration testing applications are built specifically with web-based front-ends.  Add in a few recommendations for your setup and a few places to test your hacking skills, and your recipe for hack soup is complete.
    • AI Transcript

  67. (2008)  PenTest Labs Using LiveCDs  - Thomas Wilhelm  
  68. (2008)  PGP versus PKI  - Laura Raderman  
    • Both PGP and PKI take advantage of public-key technology, but they are fundamentally different in the ways they perform key management.  The talk will start with a quick overview of asymmetric cryptography before diving into the details of how and why PGP and PKI are different, what audiences they serve, as well as how to get on the "PKI bandwagon."  The discussion will be focused on the key management and trust issues in both technologies.
    • AI Transcript

  69. (2008)  Phone Losers of America  - Murd0c, Rob T. Firefly (Rob Vincent), I-baLL (Leo), and Sidepocket (Jordan White)  
    • The Phone Losers of America's 15th anniversary panel will include video presentation of various prank calls, real-life pranks on unsuspecting businesses and people, audio prank calls, real-time questions and answers, as well as a history of prank calls, phone phreaking and the ways the PLA have gone about setting everything up.
    • PLA Media DVD  15 Years of PLA (July 2008)
    • AI Transcript

  70. (2008)  Phreaking 110: The State of Modern Phreaking  - I-baLL
    • An intermediate talk about phreaking today.  Discussion will include information about INWARDS operators and how to reach them, along with Automatic Call Distributor phone exchanges that allow anonymous access to all sorts of weird locations (911 operators, local operators, etc.) while confusing the crap out of the people on the other line as they see you coming in from nonexistent locations.  Also touched upon will be the basics of SS7, the IAM, differences between CID, CPN, and ANI plus CLIR and CLIRO.  Discussion will include Caller ID spoofing, tips on how to increase your chances of getting a fully legal tour of your local CO, and other topics such as calling supervision, telephone extenders, and weird telco tie lines.
    • AI Transcript

  71. (2008)  Phreaks, Confs, and Jail  - TProphet and Barcode  
    • In the mid to late 1990s, phreaks spent a lot of time on teleconferences (known as "confs,") created a lot of mischief, and more than a few went to jail.  Fast forward a decade and phreaks still spend a lot of time on confs, create even more mischief, and still occasionally go to jail.  Join TProphet for a walk down memory lane and into the present day, where practically any security can still be defeated by a smooth-talking social engineer.  More importantly, learn how new technologies such as VoIP can impact the trustworthiness of the telephone system (even including critical infrastructure such as 911).
    • AI Transcript

  72. (2008)  Policy Hacking: Taking Back Public Sector IT  - Arjen Kamphuis
    • On January 1, 2002, Arjen tried to access the website of the Dutch national railway (www.ns.nl) using Linux.  The site refused him access, saying it was IE-only.  This sparked a conversation with members of parliament about the need for open standards.  Over a five year period, he progressed from talking to opposition MPs to meeting the economics minister directly and was able to significantly influence national policy despite total lack of funding or any specific mandate.  As a result, the Dutch public sector will move to standardize on Open Documents Format and use open-source where comparable functionality is available in all new procurements as of 2008.  Use of ODF as a public sector document standard will be mandatory in 2009.  This talk will tell the tale of why this was accomplished, how it was done, and how others can do it too in other countries around the world.  You'll learn how to get access to the powers-that-be, how to get non-technical people interested in the subject, and how to align your policy proposals with existing policies.  While some of the political reasons for wanting open standards and open-source in government IT will be touched upon, the focus of the talk will be mainly on how to get results.
    • AI Transcript

  73. (2008)  Port Knocking and Single Packet Authorization: Practical Deployments  - Michael Rash  
    • Port Knocking and its big brother, Single Packet Authorization (SPA), can provide a robust additional layer of protection for services such as SSH, but there are many competing Port Knocking and SPA implementations.  This talk will present practical usages of fwknop in Port Knocking and SPA modes, and discuss what works and what doesn't from a protocol perspective.  Integration points for both iptables and ipfw firewalls on Linux and FreeBSD systems will be highlighted, and client-side support on Windows will be demonstrated.  Finally, advanced functionality such as inbound NAT support for authenticated connections, sending SPA packets over the Tor anonymity network, and covert channel usages will be discussed.  With SPA deployed, anyone scanning for a service with Nmap cannot even tell that it is listening; let alone target it with an exploit (zero-day or not).
    • Notes
    • Slides
    • AI Transcript

  74. (2008)  Postal Hacking  - CypherGhost  
    • A review of the United States Postal Service discusses numerous mail-related issues.  What is the heaviest thing that you can send in a flat rate box?  What happens if you mail a sphere?  What are the mysteries of digital postage meters?  A look at how modern automation allows you to send a letter 3,000 miles for only 42 cents and what security vulnerabilities might exist in that infrastructure.  How the new "PLANET" barcode will track all mail in the future.  It's all 100 percent legal, but sure to make the mailman wonder.  Postal inspectors welcome.
    • AI Transcript

  75. (2008)  Programming Your Mobile Phone for International Calling  - The Cheshire Catalyst
    • Many people are not aware of the nuances of setting up their mobile telephone for use in telephone networks overseas.  Whether they plan to call their correspondents before they leave the states, or if they plan to call friends back home once they are there, The Cheshire Catalyst will explain how to program telephone numbers in the Contact List of a mobile phone so they will work no matter where the call is placed.
    • AI Transcript

  76. (2008)  Project Telephreak  - Da Beave (Champ Clark), Slestak, Notkevin (Kevin Reilly), Gid, R0d3nt, and Jfalcon  
    • Telephreak was a group that was never meant to be.  That is, it wasn't started as a "group" or "club" for dorks.  It just ended up that way.  It started as a conference system that could be used to talk with other like minded individuals around the world.  This club of dorks now encompasses several projects, mostly due to the members' diverse interests.  These include OpenVMS clusters (public access) and VoIP related projects (Asterisk add-ons) to X.25 networks.  This panel will also be discussing "Project Telephreak" that's located in the Mezzanine area.  They will also discuss other projects currently being worked on, such as iWar, the Deathrow Project, various Asterisk projects, and non-VoIP projects.
    • AI Transcript

  77. (2008)  Pseudonymization Methodologies: Personal Liberty vs. the Greater Good  - Jon-Michael C. Brook  
    • Think of four facts that can separate you from the rest of the general populous: name, address, date of birth, or Social Security Number perhaps.  They are all likely what's currently referred to as Personally Identifiable Information (PII).  In the data privacy realm, PII disclosure is the CSI trace evidence that corporations are increasingly finding themselves as silhouettes within blood splatter patterns on the wall.  These PII disclosures may be avoided through the use of anonymization, or more importantly, pseudonymization.  This talk will focus on the history, methodology, benefits, risks and mitigations, and current players, as well as provide a demonstration of the technology.
    • AI Transcript

  78. (2008)  REAL ID Act and RFID: Privacy and Legal Implications  - Tiffany Strauchs Rad  
    • Radio Frequency Identification (RFID) is a practical and useful technology for locating items without the requisite close proximity as needed with older technology, such as bar codes.  However, new technologies such as RFID "powder," internal and external pre-crime detectors, and insertion into children's clothing and other personal items have pros and cons associated with the practicality of its use.  In addition, RFID use in access control, identification documents, and banking cards, while convenient and illegal to jam, may lack important security features to prevent unauthorized scanning and usage of the data contained.  The REAL ID Act mandates using RFID in ID cards that most Americans should carry for domestic airline travel and must carry for international travel.  This discussion will examine current RFID technology and security concerns as well as how the RFID technology implemented in REAL ID Act cards and passports may pose privacy and security risks.
    • AI Transcript

  79. (2008)  Reprimand Panel  - Gonzo DeMann (Michael J. Ferris) and I-baLL
    • One would think that, after being online for six years, an e-zine would have a few stories to tell, and the Reprimand does.  There will be nothing technical on this panel.  It will be a lighthearted look back over those six years, the beginnings of the zine, and some of the adventures that were had.  Come listen to the culture jam, and be with friends talking to friends.
    • AI Transcript

  80. (2008)  RIAA Litigations: How the Tech Community Can Help  - Ray Beckerman and Zi Mei  
    • This talk will be an update on RIAA litigations against ordinary individuals based on allegations of P2P file sharing.  It will focus on the RIAA's legal theories and how they threaten the Internet, the RIAA's reliance on "junk science" to make its case, and what the tech community can do to help.
    • AI Transcript

  81. (2008)  Safe-Cracking  - Eric Schmiedl  
    • Despite many appearances in film and television, fairly little is widely known about how safes can be opened without the proper combination or key.  This talk will attempt to address some of the questions commonly asked about the craft, such as is it really possible to have a safe open in a minute or two using just a stethoscope and some clever fingerwork?  (Yes, but it will take a bit more time than a few minutes.)  Are the gadgets used by secret agents in the movies ever based on reality?  (Some of them.)  The talk will cover several different ways that safes are opened without damage, as well as the design of one lock that is considered completely secure.
    • AI Transcript

  82. (2008)  Sharing Your Love of Technology with Normal People - Prometheus Radio Project Tips  - pete tridish and Steph99
    • Prometheus Radio Project, based in West Philly, builds radio stations with farmworkers' unions, civil rights groups, neighborhood associations, and others who want to free the media from corporate control.  They have built radio stations in Guatemala, Kenya, Mexico, and Tanzania, as well as all over the United States.  In Greek mythology, Prometheus was the one who stole fire from the gods, who had been hoarding this powerful technology, and taught humanity to use it.  Representatives from Prometheus Radio will discuss their work building radio stations and fighting to change the laws so that more groups can have access to the airwaves.  In this talk, they will particularly focus on their practices in demystifying technology with groups that lack prior technical training.  Prometheus has built 11 stations in "radio barnraisings," where over 200 volunteers converge to build a full operating radio station over a three day weekend, with most participants having never touched a soldering iron before in their lives.  While focusing on Prometheus' experience with radio, this presentation can be helpful to any nerd who has tried to explain a technical subject to people who lacked technical knowledge or skills.  Are there things that geeks can do that can help normal people share our fascination with technology?  It's magical when someone who thinks they know nothing about a technology suddenly realizes that they understand it and can use it just as well as the rich and powerful can!  Prometheus will share the tricks of popular technical education they've learned over the years.
    • AI Transcript

  83. (2008)  Simulating the Universe on Supercomputers  - Mark Vogelsberger  
    • This talk will describe recent progress in the field of cosmic structure formation and will mainly focus on computational problems and methods carrying out such large simulations on the fastest supercomputers available today.  It will also present very recent results on a new simulation of the Milky Way dark matter components.  There will be a discussion of virtual maps of gamma-ray annihilation radiation seen by a NASA satellite.  If this satellite can discover dark matter by its annihilation, this would mark a new very large step in science.
    • AI Transcript

  84. (2008)  The Singularity: Focus on Robotics and Hackers  - Ben Sgro (mr-sk)
    • The 1970s was an era of technological breakthroughs.  Exciting projects and groundbreaking discoveries were made by hackers, government, and commercial entities.  Today we should consider ourselves lucky to be sitting in the front row for the birth of the robotics industry.  Nearly 40 years after the birth of the computing industry, our lives are merged with the Internet.  Similar to the 1970s computing industry, early robotic developments are complex and their practical applications are rare.  Less than 40 years from now, our bodies and minds will be merged with the robotics and technologies we are creating today.  In our lifetime, we will see software merged with robotics that mimic humans, surpass them, and proceed to yield creations of their own.  There will be no distinction between human and machine or between physical and virtual reality.  AI, robotics, and other emerging technologies will result in the Singularity; a fundamental paradigm shift for human kind.  This presentation will dive into the Singularity, current and emerging robotics, and discuss where hackers fit into all this.  Various robotic platforms will be on display as well.
    • AI Transcript

  85. (2008)  Social Engineering Panel  - Evil Corley and Friends  
    • In a tradition that began at the very first HOPE conference, the art of social engineering will be discussed and demonstrated against random hapless victims over the telephone live for your entertainment.
    • AI Transcript

  86. (2008)  Spy Improv: Everything You Ever Wanted to Ask and Did Not Know Who to Ask - Part 1  - Robert Steele  
  87. (2008)  Starting Your Own Con for Fun and No Profit: A How-To  - Paul Schneider (Froggy) and Jodie Schneider (Tyger)
    • One of the core values of the hacker scene is the concept of DIY.  If you don't like something, whatever it is, get busy, do-it-yourself, and do it better!  In this presentation there will be a discussion of the experiences in starting Notacon in Cleveland from the ground up with little to no experience.  A look at some of the problems and pitfalls encountered, as well as some of the things Jodie and Paul did to save themselves tons of headaches.  Along the way they will touch on the concepts of taxes, law, organization, human nature, and even some of the stupid shit people have done at previous events.  This will be a discussion about what's possible in the future at other events and an inspiration for those who have an idea to throw a con to just go ahead and do so!
    • AI Transcript

  88. (2008)  Strengths and Weaknesses of (Physical) Access Control Systems  - Eric Schmiedl and Mike Spindel  
    • Access control systems are widely used in security, from restricting entry to a single room to locking down an entire enterprise.  The many different systems available - card readers, biometrics, or even posting a guard to check IDs - each have their own strengths and weaknesses that are often not apparent from the materials each vendor supplies.  This talk provides a comprehensive overview of 20 different access control technologies that focuse on weaknesses (particularly little known or not-yet public attacks) and other points that a buyer would not likely get from a vendor.  Also presented will be a model for thinking about access control systems in general that will provide a useful framework for evaluating new or obscure technologies.
    • AI Transcript

  89. (2008)  Technical Surveillance Countermeasures - A Brief Primer on the Arcane Art and Science of Electronics Surveillance and "Bug" Detection  - Marty Kaiser  
    • The spooky world of covert electronic surveillance and countermeasures by governments, corporations, and individuals is veiled in secrecy, intrigue, and myth.  Few people are well qualified to speak authoritatively about it, and fewer still are willing to.  Hear firsthand from one of the most legendary and respected wiretap and bugging experts in the United States about some of the methods and technologies used, some case studies, and the future of privacy and surveillance from an insider's viewpoint.
    • AI Transcript

  90. (2008)  Undoing Complexity - From Paper Clips to Ball Point Pens  - Matt Fiddler and Marc Tobias  
    • This talk will be a systematic approach to dissecting and disabling multiple layers of physical security in locks.  In this presentation, the focus will be on embedded design defects in high security locks, and how their discovery translates into security vulnerabilities and the disclosure of such flaws.  The attack methodology for high security locks will be reviewed.  Demonstrations will include case examples, examining tolerance exploitation, code design analysis, and leveraging the interaction of internal components within a locking system to achieve different types of bypass.  The application of this program in the development of covert, surreptitious, and forced methods of entry will be examined.  Also discussed will be the concept of responsible disclosure upon the discovery of security vulnerabilities, and how this concept applies to both those who discover flaws and to the manufacturer that produces them, and why the same concept becomes a technical, logistical, legal, and financial minefield for manufacturers.
    • AI Transcript

  91. (2008)  VLANs Layer 2 Attacks: Their Relevance and Their Kryptonite  - Kevin Figueroa, Marco Figueroa, and Anthony L. Williams  
    • Proper network infrastructure configuration is a crucial step in a successful in depth defense strategy for any organization.  The fact that the network fabric is susceptible to these attacks years after their initial discovery is alarming and disgusting at the same time.  This discussion revisits these attacks using contemporary techniques and tools and also offers equally contemporary solutions to mitigate or foil these malicious network attacks as the case may be.  Networking professionals will be able to walk away from this presentation with solid remedies to these issues and with a reinforcement that they actually still exist and are pertinent to a network security strategy that will function now and in the future.
    • AI Transscript

  92. (2008)  VoIP (In)security: Italians Do It Better  - Alessio L.R. Pennasilico  
    • Various VoIP vulnerabilities will be described here using some real case histories.  There will be a detailed explanation of how a small group of annoyed Italian VoIP hackers used the Chaos Computer Club phone network during the 2007 hacker camp for fun and profit.  Also, the story of a disgruntled employee, ways to fool bosses, how a stupid joke can turn into a social engineering attack, and what the implications might have been had the group been malicious.  Italian grappa will also be a subject of discussion.
    • AI Transcript

  93. (2008)  Warrantless Laptop Searches at U.S. Borders  - Decius (Tom Cross)  
    • U.S. customs agents have begun randomly searching the contents of laptops carried by individuals across U.S. border checkpoints.  Personal laptops contain increasingly vast and intimate collections of information about their owners, and cannot be easily sanitized for government inspection prior to travel.  The privacy implications of this policy are obviously tremendous.  There is presently a debate in the U.S. court system about the constitutionality of these searches.  This talk will cover the developments so far, explaining (and criticizing) the basic legal framework in which this debate is occurring as well as the reasoning employed by the courts that have heard this issue.  Related topics will also be discussed, such as recent controversy over the Fifth Amendment right to refuse to reveal an encryption password to the police and the Anti-Counterfeiting Trade Agreement.  Attendees will be armed with a deeper understanding of these present threats to our fundamental rights.
    • AI Transcript

  94. (2008)  What and Who is "Anonymous?"  - Alex Vanino (DeMiNe0), Dusk, Little Sister, Mike Vitale (Sethdood), PokeAnon, Atkins, and Ryan Hannigan (Dr3k)  
    • Anonymous is an anti-group which takes nothing too seriously and values free speech in the extreme.  The self-styled Anonymous (used as a mass noun) is a label and Internet meme adopted within Internet culture to represent the actions of Internet users acting anonymously toward a given agenda.  In this sense, Anonymous is "all of us, yet none of us."  The term is used in phrases such as "We are Anonymous.  We do not forgive.  We do not forget."  More recently, in 2008 specific actions were undertaken by specific group, groups, or organizations, also self-named as "Anonymous," and often associated with websites and chat systems on the Internet.  The general public's introduction to the group began with Project Chanology, a protest against the Church of Scientology.  The most visible element of the protest was mass protests of many Church sites worldwide, the first being held on February 10, 2008.  Anonymous, as a protest group, lacks a visible hierarchical structure or leaders, instead relying on individuals to contribute to the group on their own.
    • AI Transcript

  95. (2008)  Wikipedia: You Will Never Find a More Wretched Hive of Scum and Villainy  - Virgil Griffith  
    • Not only the world's largest text-based MMO, Wikipedia is a staple of the Internet user's information diet.  Because of this, (((Wikipedia))) is also laden with manipulation, forgery, and the downright unscrupulous.  In a never before seen presentation, Virgil will mine deep into the bowels of Wikipedia to unearth nefarious deeds whose perpetrators never thought would see the light of day.  New software will be released at this talk.  If you liked WikiScanner, you will like this more.
    • Slides
    • AI Transcript

  96. (2008)  YouTomb - A Free Culture Hack  - Oliver Day, Dean Jansen, Quentin Smith, and Christina Xu
    • YouTomb scans sections of sites where popular videos pop up (Digg, Technorati, YouTube, etc.) and adds these videos to a database.  This growing database is continually re-scanned and all the metadata is logged.  When a video from the YouTomb database (about a quarter million right now) goes down, it is featured on the YouTomb website.  The future of YouTomb may include: tracking geographic blocking, caching the videos themselves, tools for bloggers and people embedding YouTube clips, a search function(!), and more.  YouTomb was born at Free Culture MIT.  This session will begin as a presentation, but should quickly become an interactive discussion.
    • AI Transcript

  97. (2008)  The Zen of the Hacker  - Joshua Ginsberg
    • An inquiry into the conditions under which hacker culture thrives, the curiously American quality of hacker culture, and the evolving challenges for preservation of the hacker ecosystem.
    • AI Transcript

  98. (2008)  Closing Ceremonies  -
    • This is where it all comes to a thrilling conclusion.  In an even longer than usual finale, we'll be sharing some of the highlights and technical details of the AMD project and what we learned from our experiment of RFID-enabled badges for 1500 of our attendees.  We'll also have our entire network team on stage to let you know what succeeded this year and what didn't.  And then it's on to the actual closing down of what will certainly prove to be a most memorable conference.  Highlights will be recollected, prizes will be awarded, tears will be shed.  This is the moment where we all realize just how much fun it's been and how we can accomplish great things (like cleaning up after the closing ceremonies) if we join forces and work together.
    • AI Transcript



The Next HOPE





  1. (2010)  $2600 Meetings: Yesterday, Today, and Tomorrow  - Rob T. Firefly (Rob Vincent), Grey Frequency, Gonzo (Michael J. Ferris)
    • In this panel, longtime attendees and website admins of New York City's 2600 meeting will explain how an event that began in the 1980s as a simple way for local hackers to meet each other in person has grown into a major and vital part of the worldwide hacker community.  The panel will recap the history of 2600 meetings, and explain the basics for those interested in getting involved with an existing meeting or starting a new one.  Issues involved in operating a 2600 meeting's web presence will also be addressed.  There will most certainly be a recounting of some favorite meeting stories and experiences, and the lasting effects the meetings have had on all sorts of lives.
    • AI Transcript

  2. (2010)  American Bombe: How the U.S. Shattered the Enigma Code  - Shalom Silbermintz  
    • Many people know the story of Alan Turing and his work at Bletchley Park in designing the British bombes, the machines used to crack the German Enigma codes.  What most people don't know is what happened afterward.  When the German military added a fourth rotor to the Enigma, a new type of machine was needed in order to crack the codes and keep Allied intelligence out of darkness.  These American bombes were the first multifunction computers ever built, and are an important part of the history of modern computing.  It's the incredible, gripping story of an enterprise that rivaled the Manhattan Project in secrecy and complexity, and ultimately led to the first modern digital computer.
    • Notes
    • Slides
    • AI Transcript

  3. (2010)  Arse Elektronika: Sex, Tech, and the Future of Screw-It-Yourself  - Johannes Grenzfurthner
    • We may not forget that mankind is a sexual and tool-using species.  From the depiction of a vulva in a cave painting to the newest Internet porno, technology and sexuality have always been closely linked.  New technologies are quick to appeal to pornography consumers, and thus these customers represent a profitable market segment for the suppliers of new products and services.  Currently, all factors show that high-tech developments owe a great deal of their success to the need for further sexual stimulation.  One could cite the example provided by the science fiction concept of a full-body interface designed to produce sexual stimulation.  But it isn't science fiction anymore.  It's DIY.  As bio-hacking, sexually enhanced bodies, genetic utopias, and plethora of gender have long been the focus of literature, science fiction and, increasingly, pornography, this year will see us explore the possibilities that fictional and authentic bodies have to offer.  Our world is already way more bizarre than our ancestors could have ever imagined.  But it may not be bizarre enough.  "Bizarre enough for what?" you might ask.  Bizarre enough to subvert the heterosexist matrix that is underlying our world and that we should hack and overcome for some quite pressing reasons within the next century.  Don't you think, replicants?
    • AI Transcript

  4. (2010)  Bakeca.it DDoS - How Evil Forces Have Been Defeated  - Alessio L.R. Pennasilico (mayhem)
    • What if your infrastructure was attacked by a skilled and powerful organization, able to control many zombies all around the world?  A real case history will be analyzed, with a long trip through sleepless nights, finishing with a DIY solution using OpenBSD based servers and a bit of cleverness, all of which eventually led to a happy ending.
    • AI Transcript

  5. (2010)  Behind the Padlock: HTTPS Ubiquitous and Fragile  - Seth Schoen
    • HTTPS is finally getting adopted all over the place - including Gmail, Twitter, Facebook, Google Search, and Wikipedia - as people realize that packet sniffing is easy and credit cards aren't the only sensitive information we send over the Internet.  At the same time, a new series of attacks and scandals have shown that TLS is rather fragile.  SSL stripping lets attackers bypass sites' HTTPS-only policies; a series of scandals over the past two years has renewed skepticism of certificate authorities' role and the security of the global public-key infrastructure.  More and more people are wondering who those strange organizations are, what they're doing in our browsers, whether anyone knows if they're doing a good job, and even how to pronounce some of their names.  And recent evidence suggests some CAs may be inept - or cooperating with national governments.  Seth will explain the push to increase HTTPS deployment to protect privacy and fight Internet censorship, but also make its protections more meaningful and robust.  He'll describe the work on Firefox plugins that change the browser security model, and ideas on information sources that can supplement the certificate authorities.  The talk will also include a look at SSL Observatory, which aims to collect data to catch rogue CAs in the act.
    • AI Transcript

  6. (2010)  The Black Suit Plan Isn't Working - Now What?  - James Arlen  
    • The suit plan isn't working.  At The Last HOPE, James told you all about the awesomeness of The Black Suit.  But you're finding that it's not really working out... maybe it's possible to lower the goal?  Can we take advantage of the Econopocalypse, the fact that two years have gone by, and infiltrate the upper echelons without having to leave the Black Hat behind?  With cyber humor, blistering criticism, and awesometastic possibilities, spend some time in a discussion about ways to get to the place we all want to be - employed and happy.
    • AI Transcript

  7. (2010)  Botnet Resistant Coding: Protecting Your Users from Script Kiddies  - Peter Greko, Fabian Rothschild
    • Zeus botnets are Trojans accountable for a large percentage of all Trojan infections.  Zeus' availability and ease of use make it popular amongst malicious individuals with low technical sophistication.  Better social engineering scams, coupled with consistent levels of victim unawareness and carelessness on the part of software vendors, have created a need for greater web security.  Using a standard LAMP stack and web programming techniques, a guideline was developed to mitigate and reduce the exposure of sensitive information from compromised clients.  Because of the resultant confusion, attackers have either given up and moved on to an easier target, or have spent significant amounts of resources undoing damage to harvested POST data.  The immediate objective of implementing these new techniques is to reduce the efficacy of Zeus and its counterparts and ebb cybercrime and identity fraud.  Future use of these techniques will provide better chances against the compromising of users and web applications.
    • AI Transcript

  8. (2010)  "Brilliants Exploits" - A Look at the Vancouver 2010 Olympics  - Colin Keigher  
    • With the 2010 Winter Olympics having come and gone, it's not too late to look back at what an event it was.  From a technology standpoint, CCTV cameras and ticket sales will be looked at, and from a social standpoint, matters involving intellectual property as well as the police will be examined.
    • Brilliants Exploits - My Talk at The Next HOPE
    • AI Transcript

  9. (2010)  Build Robots and See the World  - Jonathan Foote
    • Computing and electronics parts are inexpensive enough these days to allow amateurs to build surprisingly sophisticated machines on a budget.  Jonathan will talk about his experiences building kinetic artworks like Chassis the Drink-Serving Robot and SWARM, the collection of six spherical orbs that roll without wheels.  He will discuss how it got started, how the robots work, and how knowing what you are doing is not always the best approach.  Although they haven't quite achieved world domination, he and his collaborators have exhibited robots at the Coachella Music Festival, the International Festival of Cocktail Robotics in Vienna, as well as the Techkriti Festival in Kanpur, India.  The interested beginner will wind up with a bunch of tips and sources for getting started in robotics.
    • AI Transcript

  10. (2010)  Building and Breaking The Next HOPE Badge  - Travis Goodspeed  
    • This lecture describes the design of The Next HOPE badge's hardware and firmware, as well as the security of the same.  Attendees will learn how to add a USB chip, how to reflash a badge with new firmware, and how to write new software for the device.  Additionally, attacks against which the badge is - or is not - defended will be explored in detail.  Topics will include the design of the Open Beacon firmware, forced firmware extraction, and the repurposing of badges into packet sniffers, radio jammers, Morse code beacons, and a dozen other things
    • Hacking The Next HOPE Badge
    • AI Transcript

  11. (2010)  Burning and Building Bridges: A Primer to Hacking the Education System  - Christina "fabulous" Pei
    • Public education today consists of underpaid, overworked, and generally dissatisfied teachers who are tasked with force-feeding students overwhelming amounts of information, perfectly regurgitated onto multiple-choice exams.  State exams, for their part, are written by people who understand neither content nor students.  Over the years, we have successfully created an education system that stifles creativity, stymies logical reasoning, and stunts learning.  Long gone are the days of self-motivated learning, when children used their hands and their heads, piecing the world together with all their senses.  Fortunately, we have hackers and hackerspaces.  Makerspaces and art spaces, music spaces and theater spaces.  Here are the last vestiges of true education, where individuals still take objects and learn from them - observe, break apart, analyze, fix, and piece back together.  If we can accept the productive and creative capacities of such spaces, and use them as community centers for learning, we have the potential to become the next big force in public education.  This talk will be about hacking education as we hack anything else.  That is, break the existing system, throw out what gets in the way (tests, outdated formulas, teacher-centric classrooms), reconstruct the pieces conducive to learning (inquiry, manipulatives, the outdoors, the real world, use of tools), and piece back together an education system that works for us, rather than against us.
    • AI Transcript

  12. (2010)  Buying Privacy in Digitized Cities  - Eleanor Saitta  
    • As new sensing technologies appear in our cities almost overnight, what does it mean to be visible or invisible?  What happens when socioeconomic categories determine when, where, and how you're seen?  The asymmetry in who is visible, and where, is a long-standing urban problem, but it is now being built into our technologies and our cities.  The worlds of advertising, city planning, and law enforcement are each creating their own inconsistent visions.  Privacy is not dead; rather, it is being selectively vivisected.  What can we do to fix this?  In this talk, a lot of problems and a few solutions will be covered, including the announcement of a new competition for the development of tactical countersurveillance tools.
    • Slides
    • Script
    • AI Transcript

  13. (2010)  Cats and Mice: The Phone Company, the FBI, and the Phone Phreaks  - Phil Lapsley
    • Ever since the first Blue Box arrest in 1961, the telephone company, the FBI, and the phone phreaks engaged in a long-running game of cat and mouse.  This talk explores the moves and countermoves between the two sides from 1960 to 1980, covering advances in phreaking - new ways to hack the phone system and evade detection - as well as advances in finding and prosecuting those pesky phone phreaks.  Based on exclusive interviews with phreaks, FBI agents, and telephone company security officers for his forthcoming book on the history of phone phreaking, Phil will focus on some of the more dramatic battles between the two sides that occurred during the heyday of analog phone phreaking, including the 1962 Harvard "spy ring," a certain well-known phone phreak's wiretapping of the FBI in 1975 (yes, you read that right), and the hacking of the military's AUTOVON telephone network in the mid-1970s.
    • AI Transcript

  14. (2010)  Circuitbending  - Jimmie Rodgers
    • A general overview of circuit bending, as well as its history, and some examples of really cool bends.  An assortment of bent toys will be displayed.  This talk will cover a good deal on the basics of bending, and some of the techniques used to coax the sounds out of a variety of toys.  You'll learn what to look for in bendable toys, as well as techniques that are least likely to destroy toys.  There will also be a basic workshop on circuit bending where people can build their own bent toy.
    • Notes
    • Slides
    • AI Transcript

  15. (2010)  Content of the Future  - Michael S. Hart, Greg Newby
    • There are billions of cell phones and other mobile devices, computers, and dedicated readers in the world that can be used for reading eBooks and accessing other digital content.  They may also be used for sharing, editing, annotating, and authoring.  Is the future what the inventors of the digital revolution dreamed of?  Yes and no.  While digital content can be liberated and liberating, it is also being used to turn the masses into complacent consumer zombies.  These wondrous tools for creating and sharing our own content might, at the same time, de-emphasize our ability to use the written word and logical thinking.  In this session, the father of eBooks will share his thoughts on these topics and more.  Despite corporate control and other negative forces, the liberation and proliferation of digital capabilities and content is changing the world for good, and will continue to do so.  The session will discuss how software, creative thinking, and contributed labor have created the free digital content of today.  More importantly, it will point the way to a future of content that achieves our dreams, and more.
    • AI Transcript

  16. (2010)  Cooking for Geeks  - Jeff Potter  
    • Are you interested in the science behind what happens to the food in your kitchen?  Do you want to learn what makes a recipe work so you can improvise instead of simply following a set of instructions?  In this talk, Jeff Potter, author of the forthcoming O'Reilly book Cooking for Geeks, will share the key insights into what happens in the kitchen from a geek perspective so that you can improvise and create your own unique dishes.
    • Cooking for Geeks author Jeff Potter on the Today Show
    • AI Transcript

  17. (2010)  CV Dazzle: Face Deception  - Adam Harvey
    • As CCTV camera networks proliferate worldwide, so do automated face detection/recognition systems, which can rapidly identify faces in crowds and covertly log individuals' movements.  CV Dazzle is camouflage from face detection.  It's based on the original Dazzle camo from WWI and thwarts automated face detection/recognition systems by altering the contrast and spatial relationship of key facial features.  Developed as a challenge to the growing prowess of computer vision, CV Dazzle undermines the capabilities of visual capture systems under the guise of high-fashion aesthetics.
    • AI Transcript

  18. (2010)  Design of a Wireless EMG  - Konstantin Avdashchenko
    • This talk is a summary of all the steps taken in designing a wireless EMG.  Such a device is capable of using the faint electrical signals that muscles give off when used in controlling other systems.  Konstantin's current design is a combination of power supply circuitry to run off a lithium-ion battery, a nRF24l01+ chip for wireless capability, a PIC18F4550 as the brains of the device, and an amplification board to amplify EMG signals.  This presentation will show how each of these elements come together to create a wireless EMG.  The talk will cover the sections of design, manufacture, testing, coding, and future work.
    • AI Transcript

  19. (2010)  Detecting and Defending Your Network from Malware Using Nepenthes  - Marco Figueroa  
    • Security analysts have a tendency to believe they are safe because the red alert light hasn't blinked on their IDS/IPS device.  This remains true even when organizations have invested the time and budget to deploy a myriad of different tools to defend against the overwhelming number of network defense issues we all tend to face.  A key pain point among these issues is keeping malware and the subsequent bot herders who spread it off of your corporate network.  Nepenthes is an open-source honeypot that allows for the collection of malware "in the wild."  It emulates known vulnerabilities and will download and capture the malware when it is attempting to compromise the honeypot.  This collection process allows for further analysis and understanding of the malware in question.  This presentation introduces this powerful and flexible tool and will discuss malware collection techniques attendees will immediately be able to take home and implement within their network environment and add another layer to their "defense in depth" strategy.
    • AI Transcript

  20. (2010)  Digital: A Love Story  - Christine Love, Jason Scott (Jason Sadofsky)  
    • Earlier this year, author Christine Love released a computer game called Digital: A Love Story, an interactive adventure based about BBSes, hacking, and science fiction.  Taking place in 1988, Love created a game that took place one year before she was born, utilizing textfiles.com as a research source for historical fiction.  Textfiles.com's Jason Scott will interview Christine about the inspiration and creation of this game, what the BBS era offers as a story background, and a glimpse into how future generations will look at the hackers of today.
    • AI Transcript

  21. (2010)  The DMCA and ACTA vs. Academic and Professional Research: How Misuse of This Intellectual Property Legislation Chills Research, Disclosure, and Innovation  - Tiffany Rad, Chris Mooney
    • Fair use, reverse engineering, and public discussion of research encourage innovation and self-regulates industries.  However, these principles which define our vibrant and creative marketplace are fading.  If a professional cannot constructively critique another's research online without being burdened with takedown notices until the critique is obscured or functionally removed for long periods of time, we do not have a society from which we can learn from others' mistakes and improve our trade.  Attendees will gain a greater appreciation about how the Digital Millennium Copyright Act (DMCA) is increasingly being used in ways that chill free speech, disclosure of security vulnerabilities, and innovative research.  Using hypothetical examples and discussing case law, this talk will outline procedures for counterclaiming and alternatives to removal of allegedly infringing materials, including discussing why data havens (some in anticipation of enactment of the Anti-Counterfeiting Trade Agreement) are becoming more popular.
    • DMCA Abuse and the Changing Service Landscape
    • AI Transcript

  22. (2010)  Easy Hacks on Telephone Entry Systems  - Davi Ottenheimer  
    • Telephone entry systems are practically everywhere in the city.  An investigation after a series of break-ins uncovered several shockingly simple bypass techniques currently used by criminals.  This presentation explains how the common keypad box will grant full access to a building in under ten seconds using only basic tools.  The presentation will also give details on a series of countermeasures that can significantly reduce the vulnerabilities.
    • AI Transcript

  23. (2010)  Electronic Take Back  - John McNabb
    • Discarded electronic products contain many toxic substances which can pollute the environment and threaten human health.  Many countries in the world require the manufacturer to be financially responsible for the collection and recycling of their discarded products, which provides an economic incentive to make the products less toxic and more recyclable.  More and more U.S. states are adopting electronic take back laws.  This talk will review the concept and practice of electronic take back, its track record in the E.U. and in the U.S., and why IT pros and IT security practitioners who want to support good environmental practices should support it.
    • AI Transcript

  24. (2010)  Electronic Waste: What's Here and What's Next  - Stephanie Alarcon
    • Electronic waste is a problem that dogs technology buyers, system administrators, electronics manufacturers, and especially people who engage in informal - and often dangerous and toxic - disassembly.  This talk will outline the history and scope of the problem, the environmental justice implications, the regulatory environment, industries that may be poised to face or prevent similar issues, and what we as technology workers can do to turn the tide.
    • AI Transcript

  25. (2010)  Examining Costs, Benefits, and Economics in Malware and Carding Markets  - Dr. Thomas J. Holt
    • Much has been made of the growth of online black markets in Russia and Eastern Europe that facilitate the sale and distribution of tools and information designed to subvert and compromise computer networks and users.  Specifically, web forums allow individuals to purchase access to sophisticated malicious software to victimize vulnerable systems and individuals, and sell the data they illegally obtain for a profit.  While it is clear that malicious actors can acquire myriad resources to facilitate criminal activity, it is not clear what the return on investments is like relative to the costs of buying goods and services through these markets.  This qualitative study examines this issue through an economic analysis of a sample of threads from ten active publicly accessible web forums that traffic in malware and personal information.  Specifically, this talk will consider the costs of Trojans, botnets, iframes tools, spam, DDoS services, and credit card information for victims and offenders to estimate dollar losses for victims relative to the economic gains for offenders who utilize and provide these resources.  The findings will give significant insight into the role of malware and carding forums in the problem of cybercrime and the prospective economy revolving around computer intrusions and compromises.  In turn, this talk can benefit computer security professionals, law enforcement, and anyone interested in better understanding cybercrime from the offender perspective.
    • AI Transcript

  26. (2010)  False Domain Name Billing and Other Scams  - Cheshire Catalyst (Robert Osband)
    • Telex directories have moved on.  In ancient history (the 1970s), scammers would send "invoices" to companies listed in the Telex directory, billing them for listings in their "Telex directory."  Fax machines were killing Telex, and e-mail and FTP provided the death knell.  Now those people are showing up again, sending out invoices for "domain name services."  They are not invoices, and you don't have to pay them.  A look at some of the more infamous scams of technology that people have been taken in by.
    • AI Transcript

  27. (2010)  For Its Own Sake and to Build Something Better: A Primer on Neuroscience, Bat Echolocation, and Hacker Bio-inspiration  - Scott Livingston  
    • This talk will introduce bat echolocation, in both behavioral and neuroscientific contexts, demonstrate relevance to engineered (sonar) systems, and provide a description of and results from Scott's effort to study spatial aspects of bat sonar beams.  There will also be an outline of ideas for improving ultrasound range finders (e.g., as common in robotics) and time for discussion.
    • AI Transcript

  28. (2010)  Free Software: Why We Need a Big Tent  - Deb Nicholson
    • There's been a lot of talk about diversity in free software lately.  This talk will cover why that's important and introduce some of the tactics from the political organizing world that can be used to build a successful free software project and by extension a successful free software movement.  Expect references to (((Saul Alinksy))) and Cesar Chavez as well as a bit of an introduction to free software and what it means for our increasingly technology-dependent world.
    • AI Transcript

  29. (2010)  The Freedom Box: How to Reclaim Privacy on the Web  - James Vasile
    • The world has finally realized that "spying all the time" is too high a price to pay for social networking platforms like Facebook.  Now it's up to the hacker community to respond and build a free software social networking distribution to empower end users and help them reclaim their privacy.  Software Freedom Law Center attorney James Vasile will talk about the progress of the "Freedom Box" box project and how the hacker community can get involved.
    • AI Transcript

  30. (2010)  From Indymedia to Demand Media: Participation, Surveillance, and the Transformation of Journalism  - Chris Anderson
    • In the late 1990s, advances in digital content creation and distribution raised hopes that journalism and the media were becoming radically democratized.  While these hopes have been borne out to some degree, old hierarchies and fissures are reasserting themselves as new forms of journalism become normalized.  What's more, digital technology affords more than just participation; it affords surveillance and algorithmically driven visions of consumption.  This conversational talk will address these issues, with a jumping off point being a comparison of different journalistic "visions of their audience."
    • AI Transcript

  31. (2010)  Geo-Tagging: Opting-In to Total Surveillance  - Paul V  
    • Many social networks allow users to expose geo-locational data.  For example, Twitter allows each tweet to be tagged with the GPS location of the user.  While perhaps harmless individually, once aggregated, these geo-tagged tweets can be used to build a profile of the user, revealing far more personal information than intended.  A tool that aggregates tweets and helps visualize and classify where people are tweeting from will be demonstrated and the implications discussed.
    • AI Transcript

  32. (2010)  Get Lamp Screening and Discussion  - Jason Scott
    • In the early 1980s, an entire industry rose over the telling of tales, the solving of intricate puzzles, and the art of writing.  Like living books, these games described fantastic worlds to their readers, and then invited them to live within them.  They were called "computer adventure games," and they used the most powerful graphics processor in the world: the human mind.  Rising from side projects at universities and engineering companies, adventure games would describe a place, and then ask what to do next.  They presented puzzles, tricks, and traps to be overcome.  They were filled with suspense, humor, and sadness.  And they offered a unique type of joy as players discovered how to negotiate the obstacles and think their way to victory.  These players have carried their memories of these text adventures to the modern day, and a whole new generation of authors have taken up the torch to present a new set of places to explore.  Get Lamp is a documentary that tells the story of the creation of these incredible games, in the words of the people who made them.  Director Jason Scott has previously created BBS: The Documentary, partially filmed at HOPE, and will be on hand to introduce and show the documentary, as well as talk about the production of Get Lamp and his filmmaking, including lessons learned, trivia and stories told, and how exactly one goes about minting a commemorative coin.

  33. (2010)  GPS - It's Not the Satellites That Know Where You Are  - Cheshire Catalyst
    • There are a lot of misconceptions surrounding GPS technology and how it enters into our daily lives.  Cheshire will spend this hour addressing some of this and answering all manner of questions on surveillance, new and old technology, and all sorts of other related topics.
    • Notes & Software Links
    • AI Transcript

  34. (2010)  Grand Theft Lazlow - How Hacking is Both the Death and Future of Traditional and Interactive Publishing, Journalism, and the Media  - Lazlow Jones  
    • Writer, producer and director Lazlow, who has worked on titles such as Grand Theft Auto and Red Dead Redemption, discusses how the war for net neutrality will be lost.  This talk will touch on how the battle between content creators and consumers is threatening journalism and democracy, and discuss the threats that both small publishers like $2600 Magazine and large interactive companies face in an online media landscape that expects everything for free.
    • AI Transcript

  35. (2010)  Hackers for Human Rights  - Adrian Hong
    • There are tremendous humanitarian and human rights problems throughout the world today.  While technology is generally seen as a force for good, plenty of closed societies have used technology to clamp down on their citizens and stifle human rights.  Already the fight over Internet freedom and data security has cost the lives or liberties of dissidents in countries like Iran, China, Vietnam, and Russia.  Citizens have been sentenced to long jail terms and hard labor for a critical blog posting, or accessing foreign news sites.  Creative technological efforts can combat oppressive forces, protect dissidents, journalists, and activists, and save lives.  There are some really exciting ways folks with all sorts of talents can get involved in the global effort for human rights and humanitarian improvement.  Come hear about some of the efforts that seek to help the oppressed worldwide, and how you can help.
    • AI Transcript

  36. (2010)  Hackers Without Borders: Disaster Relief and Technology  - Smokey, Elena, Dennison Williams  
    • An hour long, multimedia presentation examining the past, present, and future roles that digital and wireless technology can play on the ground during natural and manmade disasters.  This discussion will examine why government (FEMA and the National Guard) and big relief organizations (Red Cross and Salvation Army) have gotten the basic premises of disaster relief wrong, using Katrina and 9/11 as examples.  Ingenious, informal technological innovations emerging during disasters that promoted effective self-organized relief efforts will be focused upon.  The panel will also look at how the hacker communities can create novel and powerfully effective technologies to aid people, and support grassroots self-organizing during disasters.
    • AI Transcript

  37. (2010)  Hackerspaces Forever: A Panel Presented by Hackerspaces.org - Part 1  - Nick Farr, Mitch Altman, Sean Bonner, Johannes Grenzfurthner, Markuss "fin" Hametner, Alexander Heid, Nathan "JimShoe" Warner, Matt Joyce, Carlyn Maw, Far McKon, Psytek
  38. (2010)  Hacking for an Audience: Technology Backstage at Live Shows  - John Huntington
    • Working behind the scenes at live shows, you will find people with titles like Master Electrician, Audio Engineer, Automation Carpenter, or Technical Director.  These people won't likely call themselves hackers, but that's what they do: take technologies and techniques from larger industries, and appropriate, adapt, and extend them to the high-stakes, high-pressure world of live shows, where the failure of a two dollar part could cause the loss of a show and hundreds of thousands of dollars of ticket revenue.  In this industry, every night all over the world, hundreds of technicians with nerves of steel do their best to anticipate the inevitable failures which all hackers encounter, and accommodate them gracefully, preferably in a manner which the audience never even notices.  This session will cover who does what on live shows, give an overview of the technologies, and introduce some of the strategies used to ensure that the show goes on.
    • Notes
    • AI Transcript

  39. (2010)  Hacking Our Biochemistry: Pharmacy and the Hacker Perspective  - Jennifer Ortiz
    • We are complex biochemical machines.  With advances in science and medicine, we have taken to pharmaceutically hacking ourselves.  Hackers are in a unique position to understand the way we design and use drugs to manipulate disease states and to hack microorganisms that are attempting to hack us.  With drugs we send chemical instructions to biological processes to change what they do.  How do these instructions work?  How can we tweak them?  With thought-provoking examples, a pharmacy student shows how the hacker perspective is applied to our biochemistry to improve our quality of life.
    • AI Transcript

  40. (2010)  Hacking Out a Graphic Novel  - Ed Piskor
    • Having a completely different perception of hacking, cartoonist Ed Piskor discovered Off The Hook, $2600 Magazine, and many other sources related to the history of the scene.  Feeling a strong link between the minds of many cartoonists and the hackers he was reading about, he has decided to create a comic book merging these two interests.  Piskor will be talking about his creative process, the reaction that he has received within the community, and the experience of self-publishing this effort, aided by visuals from the books.
    • AI Transcript

  41. (2010)  Hacking Terrorist Networks Logically and Emotionally  - Hat Trick, Mudsplatter  
    • This presentation will touch upon broad aspects of forensics, encryption, and social engineering, and how they relate to the tracking of extremists.  Hat Trick has over seven years of experience in this very unique field, and has put together one of the world's largest open-source databases of extremist multimedia.  Topics covered include common vulnerabilities of extremist sites, the unique behaviors of extremists, how to get terrorist IPs and passwords, and what to do with them when you've got them.  Mudsplatter will discuss the psychology of manipulation, and how to gain access to even the most secure networks using simple tricks of social engineering.  Topics include how to lie with confidence, getting the paranoid to trust you, using trolling to your advantage, and some of the most common liabilities of social networking.
    • AI Transcript

  42. (2010)  Hacking the Food Genome  - Gweeds (Guido Sanchez)
    • Cooking's pretty awesome, but meatspace is such a drag!  Can't you just write a shell script to figure out what's delicious?  What would the programming language for the Star Trek Food Replicator look like?  Join Gweeds and the Food Hacking team for an in-depth demonstration of the Food Genome - an open-source culinary informatics platform used for designing menus, disassembling recipes, and visualizing the planet's taste gestalt.
    • AI Transcript

  43. (2010)  Hacking Your GPS  - Cass Lewart
    • There is more to a GPS than a pleasant voice telling you to turn right on Cedar Street, and showing a color display of adjacent ramps and intersections.  This talk will focus on the technical implementation of the current GPS system, and how the user location is derived from precise clocks on satellites.  You'll see how to capture, send, and analyze NMEA data streams exchanged between your computer and GPS.  Privacy issues, geocaching, and secret key codes required to manipulate GPS base maps will also be discussed.
    • AI Transcript

  44. (2010)  Hey, Don't Call That Guy a Noob: Toward a More Welcoming Hacker Community  - Nicolle "Rogueclown" Neulist  
    • The hacker community strives to develop and exchange cutting-edge ideas.  A key component of achieving that goal is continuing to involve new people in the community, since they can add fresh perspectives from which to view all types of hacking.  However, either because of the perception of the hacker community as something secretive or nervousness about interacting with people who are supposedly more knowledgeable, it can be a daunting experience for someone new to not only get involved, but also to want to remain involved in the community.  This talk aims to make people in the hacker community aware of the concerns that people new to it face, and provide concrete steps for building a culture of making new people feel welcomed and valuable.
    • AI Transcript

  45. (2010)  The HOPE Network  - Dragorn, Binary, Bill
    • At every last one of our conferences, something epic happens with the network we put together.  Sometimes it involves international headlines, government investigations, and emergency corporate board meetings.  Other times something spectacular happens.  Either way, we're setting aside an hour at the end of the conference to explain just what happened and how it all came to be.
    • AI Transcript

  46. (2010)  How to Bring Your Project from Idea to Reality: Make a Living Doing What You Love  - Mitch Altman
    • Mitch has brought his personal pet projects (including TV-B-Gone universal remote controls) from idea to reality, and is fortunate to make a living doing what he loves.  Mitch will outline the practical steps he took to bring his projects from a mere idea, through the steps of research, development, manufacture, sales and distribution, leading, finally, to collecting checks while in the comfort of his home (and while traveling the world).  This talk will also show some of the pitfalls of running one's own business.
    • AI Transcript

  47. (2010)  How to Run an Open-Source Hardware Company  - Limor "Ladyada" Fried, Phillip Torrone  
    • In this session, open-source hardware pioneers Limor "Ladyada" Fried of Adafruit Industries and Phillip Torrone of MAKE Magazine show how anyone can start their own open-source hardware business.  The talk will show how Adafruit runs its open-hardware business, top to bottom - from choosing a PCB (printed circuit board) manufacturer to selecting which open-source online shopping cart works best for selling electronics online.  Limor and Phil will also give a detailed overview of the top ten open-source hardware businesses, what they do, and what you can learn from their projects and products.  If you're considering turning your electronics hobby into a full-fledged business, this is a talk not to miss.
    • AI Transcript

  48. (2010)  Informants: Villains or Heroes?  - Adrian Lamo  
    • We've all seen the headlines and know that much of the controversy has a presence right here at HOPE.  For those who don't know, or who just want a summary, one of our keynote speakers, Julian Assange, the main force behind whistleblower site wikileaks.org, became a marked man after one of his sources was allegedly identified by someone within the hacker community.  The leaker had reportedly boasted to hacker Adrian Lamo (after seeing his name in a Wired article) about sending 260,000 U.S. State Department classified documents to wikileaks.org.  According to Lamo, that claim was enough to make him decide to call the authorities and become an informant.  The U.S. government became extremely interested in finding out whether Assange had these documents at wikileaks.org and it became abundantly clear that his appearance in the States to speak at HOPE would lead to interrogations, detainment, and possibly worse.  At press time, the alleged leaker (an Army intelligence analyst), was being held incommunicado in a U.S. Army brig in Kuwait pending charges.
    • Our community has been thrust into the middle of this global controversy due to the multiple connections to the various players.  There are a number of contentious questions and issues that we're all dealing with right now.  Was the leaker a hero for releasing information, including a widely sought video of U.S. troops killing unarmed Reuters staffers?  Was Lamo a hero for turning someone in who was leaking classified information?  Is wikileaks.org a vital resource or a threat to society?  How should we as a community deal with this?  And is this story being reported accurately and fairly?
    • Join us for what will be a most fascinating and enlightening panel discussion where you'll hear firsthand perspectives on the issues of leaking information and turning people in, subjects that have always been of great interest to those in the hacker world.  If you made plans to go home Sunday afternoon, this is worth rescheduling your trip and paying any penalties involved.  Trust us.
    • AI Transcript

  49. (2010)  Injecting Electromagnetic Pulses into Digital Devices  - Paul F. Renda
    • This talk is not about someone on the ground firing a ray gun at a jet and bringing it down.  This talk is about someone on the jet injecting EMP into the wiring system and causing great problems with the aviation and the black box.  This talk will have at least ten video demos of device pulses and one of a surge protector, along with explanations of a Marx generator and a MOSFET charging circuit.  Going green, fly by wire airplanes, robotic control trains, densely integrated systems' these are all realities of our daily environment.  One problem is that all of these make our lives more susceptible to an EMP disruption.  Other topics will include TWA 800, Tesla coils, Byzantine faults and the power grid.
    • Injecting EMP into Digital Devices  Video of his DEFCON 17 presentation.  
    • AI Transcript

  50. (2010)  Interaction with Sensors, Receivers, Haptics, and Augmented Reality  - Pan, Ryan O'Horo, Micha Cardenas, Azdel Slade, Elle Mehrmand, TradeMark G. (Mark Gunderson)
    • Electronic sensor technology has been increasing in resolution while decreasing in cost.  The ubiquity of GPS receivers has created the ability to obtain location-based information on demand.  At the same time, Augmented Reality interfaces are becoming more popular in the consumer market.  From the micro-level of delicate touch sensors in haptic interfaces to the macro-level of GPS positioning, these trends make physically interactive computing more and more accessible.  This session will provide an overview of motion/light/heat sensors, GPS receivers, haptic interfaces, and other interactive electronics.  Along with an explanation of how they work, several projects that utilize these technologies in the consumer, creative, and social realms will be covered.  There will be an audience participation section where users will get a chance to explore sensors and electronics themselves.
    • AI Transcript

  51. (2010)  Into the Black: DPRK Exploration  - Michael Kemp
    • North Korea scares people.  Allegedly, the DPRK has a super l33t squad of killer haxor ninjas that regularly engage in hit and run hacks against the Defense Department, South Korea, or anyone else who pisses off the Dear Leader.  The DPRK also has no real Internet infrastructure to speak of (as dictators don't like unrestricted information), although it does have a number of IP blocks.  This talk examines some of the myths about the DPRK, and some of their existing and emerging technologies.  Some of the available infrastructure associated with DPRK (funnily enough, some of which is in South Korea and Japan) will be discussed and the potential technical threats posed by a pernicious regime analyzed.
    • AI Transcript

  52. (2010)  Introduction to the Chip Scene: Low Bit Music and Visuals  - Don Miller, Peter Swimm, Joey Mariano  
    • This talk will focus on the global chip scene, an ever growing group of electronic artists that use low-bit and hacked computer and video game consoles to create music and video.  Peter Swimm of True Chip Till Death will give an overview of the chip scene past and present.  True Chip Till Death is the leading news site of the scene, providing thousands of fans with the latest news on releases, hard- and software, and live events.  Joey Mariano and Don Miller will focus on the creation of music and visuals.  Mariano, better known as Animal Style, is a musician from Philadelphia who creates music on the Nintendo Game Boy and Sega Genesis.  He will give an introduction to various trackers, the tools most chip musicians use to create low-bit music.  Miller, also known as NO CARRIER, will be discussing real-time visuals.  He'll show you how to use your Nintendo Entertainment System, the Commodore 64, and other classic hardware to create live video for chip music events.
    • AI Transcript

  53. (2010)  IPv6 Playground: New Hope Update  - Joe Klein
    • IPv6 Internet is expected to reach over 40 percent of all Internet traffic within the next four years.  With this level of growth, expectations are that many new security problems will surface, as they did with IPv4.  This presentation is an update to The Last HOPE discussion on the basics of IPv6.  The topics will include updated methods of connecting to the IPv6 Internet, an update to the protocol, new attack vectors, new defenses, and a few new vulnerabilities.
    • AI Transcript

  54. (2010)  Keeping Your Job While Being a Hacker  - Alexander Muentz
    • Hackers are curious above all other things.  While we all think this trait should be rewarded (or at least not punished so much), sometimes employers don't agree.  As a lawyer, Alex has had more phone calls than he'd like from employees who were fired once they reported a security hole - or even showed an interest in hacking.  This talk will discuss a few case studies, U.S. law, and some recommendations on how to protect your job while remaining an active hacker (or merely a curious person).
    • AI Transcript

  55. (2010)  Dan Kaminsky Keynote  - Dan Kaminsky  
    • Dan Kaminsky is one of our keynote speakers at The Next HOPE.  He has a widely respected history in the computer security world, probably best known for discovering the 2008 DNS cache poisoning vulnerability, a flaw which could allow attackers to easily perform cache poisoning attacks on any name server.  He also was key in the Sony BMG CD copy protection scandal, where Sony was found to be complicit in installing rootkits on consumer computers, making them vulnerable to all sorts of malware.  Dan estimated that Sony's rootkit had been installed on computers spanning more than 500,000 networks.  It's particularly thrilling for us to have Dan in attendance (it's also his first HOPE appearance) because he's able to present this material in an entertaining and accessible manner, unlike so many security experts who have trouble reaching an audience outside their field of expertise.  This, after all, is our goal with all of our conferences - to reach as many people with varying levels of interest and ability as possible.
    • AI Transcript

  56. (2010)  Wikileaks Keynote  - Jacob Appelbaum  
  57. (2010)  'Knock Knock Knock... Housekeeping' - The Ins and Outs of Hotel Locks  - Deviant Ollam, Babak Javadi
    • Hotels have some very unique requirements for locks.  Their systems must support many mastered levels of access, accommodate frequent turnover and reissuing of keys, enforce duration limits for access, and do all of this with relatively low cost.  For this reason, most hotels around the world have moved away from purely mechanical keys and instead rely on magstripes, perforated cards, etc.  These systems are still hackable, however, and other bypasses abound in hotel rooms... so don't think that simply locking the door after hanging a "Do Not Disturb" sign on it can provide all the privacy needed when you invite someone back to your room later!
    • AI Transcript

  58. (2010)  Light, Color, and Perception  - Jonathan Foote
    • The phenomenon of color has fascinated great minds from Newton to Picasso, and its complexities are still being unraveled.  To understand light and the perception of color, you need physics, biology, psychology, and aesthetics - and this talk will cover a little about all of them.  Along the way, topics will be touched upon like non-spectral colors, different color spaces, why laser light looks "speckled," color-based optical illusions, and an intuitive explanation of the mysterious CIE chart.  This material is rarely covered in either art or science classes and is a fascinating intersection of both.
    • AI Transcript

  59. (2010)  Lisp, The Oldest Language of the Future  - Adam Tannir
    • Being the second oldest high-level language still in widespread use (after Fortran), Lisp is often considered solely as an academic language well-suited for artificial intelligence.  It is sometimes accused of having a (very (strange syntax)), only using lists as data types, being difficult to learn, using lots of memory, being inefficient and slow, as well as being dead, an ex-language.  This talk, focusing on Common Lisp, aims to show that it is actually an elegant, unique, expressive, fast, extensible language for symbolic computation that is not difficult to learn and may even change the way you think about programming.  Lisp is primarily a functional paradigm language, but supports object-oriented, imperative, and other programming models natively.  Rapid prototyping, iterative development, multiprocessor development, and creation of domain-specific languages are all facilitated by Lisp.  There will be a discussion of the origins and history of Lisp, followed by a demonstration of the language, features that migrated to and from other languages, and concluding with a look to what may be in store for the future.
    • AI Transcript

  60. (2010)  Locational Privacy and Wholesale Surveillance via Photo Services  - Ben Jackson
    • With the plethora of third-party services that allow folks to post photos to their Twitter account, how hard would it be for someone to stalk a person's location via the GPS metadata tagged in their images?  Mayhemic Labs did the research and it turns out the answer is - not very.  Over the past few months, Mayhemic Labs has amassed a sizable database of people using these services - and what geographic information has been encoded on their publicly available photos.  This presentation will cover the basics of how and why this research was done, why sharing such information is bad, why privacy is hard to get right, attempts at public outreach at ICanStalkU.com, how you can replicate such a system, and various instances of privacy fail.  Also, tools will be released that will allow you to test your own (or other people's) photo streams.
    • AI Transcript

  61. (2010)  Lock Bypass Without Lockpicks  - Dan Crowley
    • You train as hard as you can, picking lock after lock, learning about all the different picks, different picking techniques and styles, anti-picking features, and how to manipulate them... then some guy with a screwdriver takes the hinges off the door faster than you can pick the doorknob.  That's right, there are ways to bypass locks which don't involve direct manipulation of the pins, and they not only tend to be easy, but fast.  This talk follows the story of Waldo, one hard-to-find hacker trying to wrestle the truth from the jaws of a shady corporation peddling suspicious medication.  Waldo, having been captured and stripped of his picks, must escape using only his wits, and whatever he can find on his way out.
    • AI Transcript

  62. (2010)  Memory Fun 101 - Memory Training for Everyone  - Chester Santos  
    • A powerful memory can be an invaluable asset in life.  Memory is absolutely fundamental to learning, so improving one's memory can have a profound positive impact on both academic and job performance.  This seminar will entertain and educate attendees, while helping them to develop valuable memory skills that will enrich their lives.  In this fun and entertaining program, 2008 USA National Memory Champion Chester Santos will teach attendees the basics of memory improvement.  Attendees will learn a number of memory boosting methods that will exercise their imagination and awaken their creativity.  Participants will be shown how to utilize both sides of their brain in order to make information stick and become unforgettable.  Attendees will participate in enjoyable exercises and will actually be able to feel their memory ability improving throughout the seminar.  Everyone will leave this seminar with sharper minds and a solid foundation in exercises and techniques that will benefit them throughout their lives.  Talk about providing HOPE!
    • AI Transcript

  63. (2010)  Modern CrimeWare Tools and Techniques: An Analysis of Underground Resources  - Alexander Heid  
    • This talk will highlight the features, functions, availability, and impact of modern crimeware tools.  The talk will have a specific focus on the Zeus payload and command/control application, and will touch upon other leading banking malware.  In addition to detailed technical information, the talk will highlight the history and evolution of this particular Trojan and the underground economy that drives it.  Furthermore, there will be discussion of other tools that are often used in conjunction with the payload, such as remote exploit kits.  The talk will also highlight mitigation techniques and basic design principles for web applications and server configurations that can help reduce the impact of crimeware on individuals and organizations.
    • AI Transcript

  64. (2010)  Monkeysphere: Fixing Authentication on the Net  - Daniel Kahn Gillmor, Jameson Rollins
    • Most modern public-key infrastructure is built around notions of centralized authority, which is troublesome for those of us who want decentralized secure communications on the global network.  Monkeysphere is a project to extend the OpenPGP Web of Trust into as many domains as possible, effectively supplanting hierarchical certification infrastructure like X.509, and restoring control over authentication and identification to the communications peers themselves and their own legitimately trusted introducers.  Functional tools for authenticating peers over the World Wide Web and SSH have been introduced, with plans for more protocols.  Come learn how the tools work, how you can take advantage of the Web of Trust in your own projects, and how you can contribute to building a more autonomous and decentralized global network.
    • AI Transcript

  65. (2010)  Much Ado About Randomness  - Dr. Aleksandr Yampolskiy
    • Access to random bits is required by almost every security protocol.  A common assumption in cryptography is that all parties have access to a perfect random source.  Then we can prove that signatures are unforgeable, SSL is secure, and life is good.  In practice, the situation is quite different as demonstrated by recent exploits of Debian OpenSSL library, WEP, and Netscape 1.1 keys.  This talk will try to bridge the gap between theory and practice.  The discussion will include what it means for a number to be "random" and demonstrate how some open-source tools, as well as custom tools, can be used to find programs with poor sources of randomness.
    • AI Transcript

  66. (2010)  The Need for a Computer Crime Innocence Project  - Joe Cicero, Alexander Muentz, Seth Schoen
    • High profile computer forensic cases like those of Julie Amero and Michael Fiola, where innocent people were falsely charged with downloading illegal files, illustrate the need for professional forensic standards for determining whether a user, or malware infecting their computer, downloaded suspect files.  Joe Cicero discusses his experiences dealing with his college administration, attorneys, and the EFF over the problematic research issues that willful installation of malware brings about.  He will discuss his project outline and testing protocols and procedure, detailing why certain decisions were made.  Audience feedback will be requested on how to create an innocence project designed specifically for computer crime cases.  Tech-savvy criminal defense attorney Alex Muentz and EFF's Seth Schoen will round out the panel with their insights.
    • AI Transcript

  67. (2010)  Net Wars Over Free Speech, Freedom, and Secrecy or How to Understand the Hacker and Lulz Battle Against the Church of Scientology  - Gabriella Coleman, Finn Brunton
    • Following a brief lecture on Project Chanology, the question will be posed: how can we harness the power of lulzy virality, of pleasure, of trickery, of spectacular trolling for purposes above and beyond sharing the wisdom of Advice Dog?  It'll start with a brief look at great activist media in the past, from Guernica and the picture of the whole Earth to projects by The Yes Men - how they spread ideas and helped people get informed, organize, and act.  What makes the creation of lulzy memes different?  Learn about how to create exploitable forms and rapid variations, and mechanisms for bringing the best stuff forward.  Can we make media memes with goals beyond lulz, and teach activists who've never heard of 4chan to make them too?  Part lecture, part workshop, this will feature cameos by Rageguy, Pablo Picasso, V, alt.pave.the.earth, Kathe Kollwitz, Courage Wolf, Stewart Brand, Sarah Palin, Batman, Goya, Philosoraptor, Adolf Hitler, Trollface, Shepard Fairey, Joseph Ducreux, David Cameron, lots of Spartan warriors, and lots and lots of (trollish) cats.
    • AI Transcript

  68. (2010)  No Free Lunch: Privacy Risks and Issues in Online Gaming  - Don Tobin, Lyndsey Brown
    • Online gaming has been growing significantly over the past ten years.  There are currently an estimated 1.5 billion unique registered accounts of online games worldwide.  However, few people are aware of the risks associated with playing online games.  The risks are also not limited to users in their own homes on their own personal computers.  Many of these games are being played in the workplace, opening up a whole different set of risks.  This research is an initial look at three popular online games - and the potential risks they pose.  This initial work was broken into three tasks: analyze the posted privacy policy, terms of use/service, and other related documents of each game; install the game and analyze system changes; and monitor firewall traffic of game-related processes, especially when we are not even using the particular game.
    • AI Transcript

  69. (2010)  The OpenAMD Project  - Aestetix, Travis Goodspeed, Echo, Mitch Altman, Far McKon, cpfr  
    • The badge for The Next HOPE is the result of a collaboration of several people over the last 11 months.  Hardware, software, social interactivity, and more.  This panel will cover how the badge works, how we keep track of where you are at the conference, what cool games you can play, and perhaps some clues to a few of our kule s3cr3ts.
    • AI Transcript

  70. (2010)  Own Your Phone  - TProphet (Babu Mengelepouti)
    • Ever wonder what makes your phone work... and how to make it work in ways that were never intended?  You might be a phreak!  Phreaking is one of the most exciting and fastest-changing scenes in the hacker landscape.  Join TProphet and phriends for a phun look at some of the newest innovations.
    • AI Transcript

  71. (2010)  Privacy is Dead - Get Over It - Part 1  - Steven Rambam (Steven Rombom)  
    • Privacy is Dead - Get Over It - Part 2
    • This will be a wide-ranging lecture covering databases, privacy, and "computer-aided investigation."  This talk will include numerous examples of investigative online resources and databases, and will include an in-depth demonstration of an actual online investigation done on a volunteer subject.  Emphasis will be placed on discussing the "digital footprints" that we all leave in our daily lives, and how it is now possible for an investigator (or government agent) to determine a person's likes and dislikes, religion, political beliefs, sexual orientation, habits, hobbies, friends, family, finances, health, and even the person's actual physical whereabouts, solely by the use of online data and related activity.  The final half hour of the talk will be devoted to Q&A.
    • AI Transcript

  72. (2010)  PSTN-Based Cartography  - Da Beave (Champ Clark), Jfalcon
    • Sun Microsystems use to say, "The network is the computer."  This talk will focus on that "other" computer.  The neglected computer.  The PSTN (Public Switched Telephone Network) "computer."  Throwing VoIP into the mix, it's never been easier to "map" that neglected "computer."  This talk will discuss how to map the "Human Network" as well as new techniques in automated PSTN network scanning including more X.25 network goodies.  This is the second part of "Hacking International Networks using VoIP" from The Last HOPE.
    • AI Transcript

  73. (2010)  Radio Reconnaissance in Penetration Testing - All Your RF Are Belong to Us  - Matt Neely
    • Tired of boring old pen-tests where the only wireless traffic you see is 802.11 and maybe a little Bluetooth?  With this amazing new invention, the radio, your eavesdropping options can be multiplied!  Come to this talk to learn techniques for discovering, monitoring, and exploiting a wide array of radio traffic with real world examples illustrating how these techniques have been used to gather information on a target's physical security, personnel, and standard operating procedures.
    • AI Transcript

  74. (2010)  Reach Out and Touch Face: A Rant About Failing  - Johannes Grenzfurthner  
    • Hackers love knowledge.  They try to find out how stuff works.  And that's great.  Experimentation is a major part of hacking.  It is in the most philosophical sense a deconstruction of things.  A specific use is never inherent to an object, even though technical demagogues like to claim that it is.  Just compare the term "self-explanatory" and the term "archeological find."  It's a pretty hard task to find out what technology is and what it should do if you don't have a clue about the context.  Usually the use is connected with the object through definition ("instructions for use").  Turning an object against the use inscribed in it means probing its possibilities.  Science and Technology Studies (especially Langdon Winner and Bruno Latour) have convincingly demonstrated that the widespread inability to understand technological artifacts as fabricated entities, as social and cultural phenomena, derives from the fact that in retrospect only those technologies that prove functional for a culture and can be integrated into everyday life are "left over."  However, the perception of what is functional, successful, and useful is itself the product of social and cultural, and, last but not least, political and economic processes.  Selection processes and abandoned products (developmental derailments, sobering intermediary results, useless prototypes) are not discussed.  Well.  What can we do?  We can fail.  Beautifully.
    • AI Transcript

  75. (2010)  A Red Team Exercise  - Tom Brennan
    • Shall we play a game?  This talk will focus on full scope security assessments and stealing intellectual property in five easy steps.  It will take the form of a game that divides the audience into attack and defend teams for a builder vs. breaker educational workshop.  Included in the discussion will be physical, electronic (network, application, wireless, telecom, and cellular), and intelligence gathering techniques used for offensive projects.
    • AI Transcript

  76. (2010)  Risk Analysis for Dummies  - Nick Leghorn
    • We all get that "gut feeling" about what is risky, but how do we communicate that to managers or other people in a meaningful way?  And how can we determine what risks are worse than others in a justifiable manner?  How do you even define "risk?"  In this talk, you'll learn about the most up to date methods of identifying risk, evaluating risk, and communicating risk to others, as well as some models used by the U.S. government and others to identify attack targets, evaluate building security, diagram attacks, and more.  And no math problems harder than simple addition, guaranteed.
    • AI Transcript

  77. (2010)  Rummaging in the Government's Attic: Lessons Learned from More Than 1,000 Freedom of Information Act Requests  - Phil Lapsley, Michael Ravnitzky
    • Phil and Michael will conduct a guided tour through GovernmentAttic.org, a website that has (legally!) obtained and published hundreds of interesting government documents obtained via the Freedom of Information Act (FOIA).  Based on extensive interviews with the site's creators and through a half dozen examples they will describe some of the clever FOIA tools and techniques (hacks, in other words) that the site has employed to obtain informative, valuable, and sometimes even amusing documents and datasets from government agencies.  They will also highlight similarities between the mindsets and approaches of hackers and successful FOIA requesters.
    • AI Transcript

  78. Saturday Night Hacker Cinema  -
    • At press time, there were all sorts of rumors flying around about leaked hacker films and other brand new presentations that few have seen.  While we can't say with certainty what we'll be showing, we most definitely can say that it'll capture your attention and be a unique window into the wonderful world of hackers.

  79. (2010)  Shodan for Penetration Testers  - Michael "theprez98" Schearer
    • Shodan is a computer search engine unlike others.  Instead of scouring the web for content, Shodan scans for information about the sites themselves.  The result is a search engine that aggregates banners from well known services.  For penetration testers, Shodan is a potential game changer as well as a gold mine of potential vulnerabilities.
    • AI Transcript

  80. (2010)  The Simpsons Already Did It - Where Do You Think the Name "Trojan" Came From Anyway?  - Sandy Clark (Mouse), Matt Blaze, Bill Cheswick
    • SMS blockers, ransomware, licenses for Trojans, factory installed malware... every day the news is full of accounts of innovative threats altering the landscape of the security arms race.  But are these attacks really new?  A quick glance at history shows us that these same attacks and defenses have been around for as long as there have been humans.  Come hear about the ancient Greek firewalls (and firewall bypasses), about Roman security-by-obscurity, ancient port-scanning, and about Mozart's "rights amplification" against the Pope.  This will be a trip through the ages as the security arms race is analyzed.  You'll discover how we got where we are today and learn that even in security, history is always repeating itself.
    • AI Transcript

  81. (2010)  Sita Sings the Blues: A Free Culture Success Story  - Nina Paley
    • "If it's free, how do you make money?"  One year after the Copyleft release of her animated musical feature Sita Sings the Blues, Nina Paley presents the latest round of hard data from the project.  Contrary to MPAA propaganda, the more the audience freely shares the film, the more they purchase DVDs, theater admissions, and merchandise.  In this talk, witness the numbers that prove it.
    • AI Transcript

  82. (2010)  Smartphone Ownage: The State of Mobile Botnets and Rootkits  - Jimmy Shah
    • Symbian Botnet?  Mobile Linux Rootkits?  iPhone Botnets?  Millions of phones at risk?  The press coverage on smart phone threats is at times somewhat accurate, distant, and occasionally (if unintentionally) misleading.  They tend to raise questions such as: How close to PC levels (100,000+ to millions of nodes) have mobile botnets reached?  Have mobile rootkits reached the complexity of those on the PC?  This talk will cover the state of rootkits and botnets on smart phones from the perspective of anti-malware researchers, including demystification of the threat from mobile rootkits and mobile botnets, the differences (if any) between mobile rootkits and mobile botnets vs. their PC counterparts, and a look at how samples seen in the wild and researcher PoCs function.
    • AI Transcript

  83. (2010)  Snatch Those Waves: Prometheus Radio and the Fight for Popular Communications  - Pete Tridish, Maggie Avener
    • The Prometheus Radio Project started with radio pirates fighting for local groups to be able to run community radio stations, and over the years has sued the FCC to stop media consolidation, built stations in places like Venezuela and Tanzania, and experimented with using off-the-shelf wireless technologies to do for hundreds of dollars what commercial stations spend tens of thousands for.  This panel will help bring you up to date on the political debates in Washington about low-power FM, open spectrum, and IBOC digital radio.  They will talk about epic radio barnraisings where hundreds of people are brought together to build a new radio station over the course of a single weekend - and their plan for the next barnraising in the Hudson Valley.
    • AI Transcript

  84. (2010)  Social Engineering Panel  - Emmanuel Goldstein and Friends  
    • People have been known to come to HOPE just for this panel, in which the history, stories, and demonstrations of social engineering are laid out for all to see - and hear.  Something will invariably be revealed over the telephone by someone who really should know better in our traditional live demonstration that never fails to entertain.
    • AI Transcript

  85. (2010)  Spy Improv on Steroids - Steele Uncensored - Anything Goes - Part 1  - Robert Steele  
  86. (2010)  The State of Global Intelligence  - Robert Steele
    • Our first speaker at our first conference back in 1994 is back to once again presents an overview of global intelligence.  Smart Cities, Smart Corporations, Smart Nations are the ideal.  The "tribes" of intelligence - academic, civil, commercial, government, law enforcement, military, and non-governmental - are almost catatonically stupid as well as corrupt in their information pathologies.  There will also be a brief overview of his new book, Intelligence for Earth: Clarity, Diversity, Integrity, and Sustainability, which, like all of his books, is free online and for sale at cost at Amazon.
    • AI Transcript

  87. (2010)  Surf's Up!  Exploring Cross Site Request Forgery (CSRF) through Social Network Exploitation  - Daniel McCarney  
    • Web application security has progressed by leaps and bounds since first being discussed in the early 2000s.  XSS, SQLi, Directory Traversals, and other traditional attacks are becoming more widely understood by a greater demographic of developers.  Unfortunately, we are just scratching the surface.  There still exists a great number of attack vectors that are ignored.  Cross Site Request Forgery is a prime example of this.  It is a simple technique with powerful implications ranging from denial of service and firewall bypass to full blown site compromise.  The theory of CSRF will be presented here in simple to understand terms.  An example of a virulent exploit of a real-world social networking site (Vampirefreaks.com) using CSRF will also be shown.
    • Slides
    • AI Transcript

  88. (2010)  T+40: The Three Greatest Hacks of Apollo  - Stephen Cass
    • Forty years ago, manned exploration of the moon was in full swing.  The three greatest hacks of the Apollo program occurred on Apollo 12, 13, and 14, in two cases saving the mission, and in one case saving lives.  Drawing on personal interviews with the engineers involved and archival records, this talk will look at the technical aspects of each hack, including largely overlooked, but critical, details of how the lunar module was prepared for lifeboat mode during the Apollo 13 crisis.
    • Apollo 13, We Have a Solution
    • AI Transcript

  89. (2010)  The Telephone Pioneers of America  - Kyle Drosdick  
    • The Telephone Pioneers of America is an organization of mostly retired employees of the Bell System and affiliated companies.  They remain active in the community as an organization that promotes their history and industry.  You can find them in many communities across the nation, often in the very cities and neighborhoods they spent their careers working in.  The pioneers have amassed lifetimes of wisdom working on the telephone system and intimately understand the technology and politics of it.  The telephone company will never be what it was when they were employed there and they know that the next generation of pioneers may not ever actually work for "the company" as they did.  Using photographs, recordings, and artifacts, this unique treasure will become accessible to members of the audience, especially younger individuals who may not ever have used what is now vintage telephone equipment - like rotary dial phones.  There will be a selection of functional and historically significant equipment for attendees to learn about and enjoy thoroughly.  This talk is intended to help bridge the gap between hacker and pioneer.
    • AI Transcript

  90. (2010)  Tor and Internet Censorship  - Jacob Appelbaum, Seth Schoen  
    • The Tor project has seen an increased focus on Internet censorship as many more users adopted Tor to get around blocking.  In the past year, Tor was a popular means of bypassing censorship in Iran, China, and around the world.  Firewall operators have been noticing.  Tor has also had to contend with new organized efforts to block access to the network, and has rolled out the "bridges" blocking-resistance system in earnest.  Alongside the perpetual need to get more Tor nodes, it's become important to get users to run bridges - and to experiment with ways of communicating bridge addresses to users affected by censorship.  The current censorship landscape will be explored, along with the bridge mechanism and efforts to recruit more bridges.  There will also be an update on how Tor developers are responding to the growing pains and dealing with scaling challenges associated with Tor's popularity.  You'll also hear about the challenge of counting the number of users on an anonymity network, and how client software can force the use of encryption to protect users from some attacks after their traffic leaves the Tor network.
    • AI Transcript

  91. (2010)  Towards Open Libraries and Schools  - Gillian "Gus" Andrews, Jessamyn West, Ellen Meier  
    • You can wear your "No, I won't fix your computer" shirt, or you can try to make progress with the bureaucrats, teachers, bosses, and other tech n00bs who make maintaining the systems in your life utterly frustrating.  In this panel, organized and moderated by Off The Hook participant Gus Andrews, two veterans of the battle to wire under-served areas talk about what works and what doesn't when helping the uninitiate learn about the Internet, privacy issues, security, and proprietary software.  Jessamyn West, blogger at librarian.net and a MetaFilter manager, will talk about her efforts to educate librarians and patrons about the PATRIOT Act and digital literacy, and her technology advocacy with the American Library Association.  Ellen Meier, a professor at Columbia University Teachers College who presses for greater access to the Internet and more pervasive use of technology in classrooms, will talk about what works and what doesn't when working with educators and with administrators in Albany.  The panel will welcome discussion, questions, and frustrations from audience members dealing with similar problems.
    • AI Transcript

  92. (2010)  TrackMeNot: Injecting Reasonable Doubt in Everyone's Queries  - Vincent Toubiana
    • TrackMeNot is a lightweight Firefox extension that helps protects web searchers from surveillance and data-profiling by search engines.  It does so, not by means of concealment or encryption (i.e., covering one's tracks), but instead, paradoxically, by the opposite strategy: noise and obfuscation.  Because any query can plausibly be artificial, everyone's search history ownership is now subject to a reasonable doubt.  The challenge that TrackMeNot encounters is to search as a human.  The adversary, a search engine capable of mining billions of user queries, should not be able to filter the artificially generated queries.  Ideally, even a human should not be capable of filtering the queries that have been injected.  This talk will also detail the motivations in developing TrackMeNot: lack of transparency of search engines' use of data and ambiguity of the privacy policies.  Key elements of TrackMeNot implementation will be described and evidence will be revealed proving that a major search engine profiling algorithm is influenced by the use of TrackMeNot.
    • AI Transcript

  93. (2010)  Video Surveillance, Society, and Your Face  - Joshua Marpet
    • Video surveillance is pretty simple.  Point a camera at something, watch the stream.  But the technology has been integrating into our daily lives.  From Makeababy websites, to "change your race" kiosks, facial recognition and the technology spawned from video surveillance is creeping into our lives.  The police have taken notice of this, and are starting to interpret laws that make it difficult to photograph them legally.  Do these technologies and laws imperil your privacy, your rights as a photographer, or even your life?  This is a talk about where these technologies are going, how to stay out of jail, and how to keep your face out of official databases.
    • AI Transcript

  94. (2010)  Vintage Computing  - Evan Koblentz, Bill Degnan  
    • Many people believe Silicon Valley is where the most significant early developments in computers occurred.  But the New York/New Jersey/Pennsylvania area was home to many major developments in microcomputer history.  See and hear amazing historical and technical achievements of the computing pioneers of our region in the context of how we use computers today.  Presenters will also present a comprehensive working exhibit of several early microcomputers all day Saturday.
    • AI Transcript

  95. (2010)  Why You Should Be an Amateur  - Ben Jackson
    • Lots of people think the "maker culture" is a relatively new phenomenon.  However, one group has been doing it for close to 100 years: amateur radio operators.  While some dismiss amateur radio as an aging artifact from decades ago, today's radio amateurs are putting together wide area wireless networks, developing digital protocols that use the tiniest amount of bandwidth, and building radios from scratch.  This presentation will review the basics of amateur radio, the advantages over unlicensed devices, and areas of interest you can apply to your existing projects.
    • AI Transcript

  96. (2010)  Wireless Security: Killing Livers, Making Enemies  - Dragorn (Michael Kershaw), RenderMan (Brad Haines)
    • The message that wireless is unsafe has permeated the IT zeitgeist, however people still forget client devices.  This talk by Dragorn and Renderman moves away from guarding the access points to guarding the clients.  Considering the fun that is continually had by the authors at airports and public networks, this is a message that needs to get out.  Attacks targeting client devices are becoming more sophisticated.  Kismet Newcore makes breaking WEP a passive action.  Airpwn has received a facelift and is now capable of more unspeakable actions over open links (hotels, airports).  Karma as well is flypaper for clients running wireless without any thought to protection.  Recent vulnerabilities in browsers and other protocols that are often dismissed as "too hard to exploit to be useful" are suddenly very possible and dangerous when wireless is involved, and attacks crossing from Layer 2 directly to Layer 7 vulnerabilities will be shown.
    • AI Transcript

  97. (2010)  Closing Ceremonies  -
    • This is really worth sticking around for, as so many people do.  Sure, there are those who leave early on Sunday because they have to get back to whatever it is they do in the real world bright and early Monday morning.  But if you fancy something a bit more celebratory and different, we suggest you stick around as the conference truly winds down.  This is where you hear some of the back story of the conference, get a chance to win some prizes, and hopefully help us put the hotel back in the state in which we found it.  Maybe even a better state.
    • Speaking of the hotel, at press time it appears that a major public hearing will be taking place the day after HOPE concerning the proposed demolition of the hotel where public opinion will be sought.  If this remains the case, there will never be a better opportunity to show those in charge how important the Hotel Pennsylvania is to the world.  You don't have to be from New York to participate - in fact, the more people from all parts of the globe who speak up, the better.
    • We hope to see even more people than the usual huge mob for this special closing.
    • AI Transcript



HOPE Number Nine




  1. (2012)  Lightning Talks  - Various
    • A dozen talks over two days, each around five minutes in length.  These were presented after the Friday and Saturday keynote addresses.
    • AI Transcript

  2. (2012)  3D Printing: Making Friends in DC Before People Start Freaking Out  - Michael Weinberg
    • This talk is about protecting 3D printing from industries that are not excited about disruption.  It will begin with an overview of the technology behind 3D printing and how the industry is developing and diversifying.  It will then cover how Intellectual Property (IP) relates to 3D printing, and highlight the opportunities that 3D printing gives us to rethink the permission culture that has developed alongside the growth of digital copyright.  The talk will end with a description of current IP conflicts connected to 3D printing and examples of steps being taken today to win allies among policymakers in Washington, D.C.
    • 3D printing has the possibility of being a widely disruptive and beneficial technology, and the last 15 years have taught us that not everyone embraces widespread disruption.  It is possible that industries disrupted by 3D printing will react along the lines of those disrupted by the Internet (negatively).  Fortunately, today we have the opportunity to consider what could have been done in the early days of the Internet to insulate it from some of the legal and policy attacks in D.C.  HOPE attendees and the hacker community at large will benefit from beginning to think through these issues today - before a problem occurs.
    • AI Transcript

  3. (2012)  Activist DDoS Attacks: When Analogies and Metaphors Fail  - Molly Sauter
    • What are we talking about when we refer to activist Distributed Denial of Service (DDoS) attacks?  Digital sit-ins?  Juvenile bullying and censorship?  Something completely different?  The rhetorical framings by both advocates and critics of activist DDoS attacks have ultimately fallen short of successfully defining DDoS as an activist tactic.  Metaphoric characterizations have failed to describe the reality of activist DDoS attacks, and new analysis is needed if we are to fully understand the tactic's potential.  In an effort to come to this new analytical understanding, this talk examines the history of DDoS attacks in activism in general, culminating with the case study of the Anonymous Operation Payback attacks.  The discussion will show how the population participating in DDoS attacks has shifted from a professionalized activist core and their peers (such as those participants in the Electronic Disturbance Theater's actions in the 1990s and 2000s) to the diffuse, less professionalized, and less conventionally politically active population that participated in the Anonymous actions.  The role the media has played in past activist DDoS actions will also be explored.  Evidence will be presented to show that DDoS attacks have shifted in their tactical nature from electronic direct action to a form of media manipulation.
    • AI Transcript

  4. (2012)  Advanced Handcuff Hacking  - Ray
    • Handcuffs always have been a special kind of challenge to lockpickers.  This talk will cover advanced manipulation techniques including improvised tools, hidden and 3D-printed keys, and exploiting design weaknesses of various handcuff models.  Also, the newest handcuffs produced in the United States and Europe will be shown and explained, some of which haven't even been introduced to police forces yet.
    • AI Transcript

  5. (2012)  Advancements in Botnet Attacks and Malware Distribution  - Aditya K. Sood, Rohit Bansal
    • Third Generation Botnets (TGBs) have circumvented the normal stature of the World Wide Web.  These botnets harness the power of the HTTP communication model to complete their stealthy operations.  To automate the exploit distribution mechanism for infecting users on a large scale, TGBs are collaborating with Browser Exploit Packs (BEPs).  TGBs include Zeus, SpyEye, and the present-day botnet ICEX that are explicitly using BEPs such as BlackHole and Phoenix for insidious infections.  Several cases of large scale infections have been seen in the recent past.  Additionally, TGBs are designed with sophisticated attack techniques such as form grabbing, Ruskill, Web Injects (WI), Web Fakes (WF), DNS tampering, and other custom plug-ins to steal information.  These attack techniques are heavily relied upon in the Man-in-the-Browser (MitB) paradigm.  The infection strategies include programs such as spreaders that infect other software to conduct drive-by-download/drive-by-cache attacks.  This talk delves deep into the design of present-day malware and advancements in attack techniques and infection strategies and is an outcome of real-time case studies.  Several demos will be shown to back up the arguments.
    • AI Transcript

  6. (2012)  An Aesthetic Critique of Fictional Media  - Sean Mills, Syl Turner
    • This survey of visuals used in motion pictures explores their design implications.  Motion pictures play a unique role in constructing how we use terminals, interfaces, and graphic design itself.  Highlights will include a tour of multiple screen arrays as found in Star Trek, Brazil, The Truman Show, and Iron Man; a collection of simulated environments from Johnny Mnemonic, Tron, Hackers, and The Matrix; as well as a suite of metamedia from The Final Cut, Brainstorm, and Minority Report.  This presentation catalogs the digital artifacts of the past and present, while asking: What are limitations on graphic design?
    • AI Transcript

  7. (2012)  Anti-Censorship and Anti-Surveillance Tools - Improving the Landscape  - James Vasile
    • Every day, world news informs us of more and greater threats to free communication.  Nations increasingly restrict network traffic at their borders.  Surveillance is omnipresent in almost every country and also via companies who defend ubiquitous spying as "best practices."  This mass privacy intrusion has spurred development of a number of open-source tools even as that development has revealed a need to address common obstacles faced by circumvention tools projects.  This talk describes some of those common obstacles and current work to fix them on a community-wide basis.
    • AI Transcript

  8. (2012)  Anti-Censorship Best Practices: How to Make Keeping It Up Easy and Taking It Down Hard  - maymay
    • What do bananas have to do with censorship?  What do polyamorous people have in common with fax machines?  How can you help your ideas have cyber-sex?  In today's age of postmodern warfare, information itself can be a "weapon of mass destruction."  As corporations and repressive governments track, monitor, and ultimately crack down on their own citizens, employees, and independent publishers, information depicting everything from political speech to cartoon drawings of religious icons is becoming increasingly rationed and ever more tightly controlled.  But nowhere is this more apparent than the realm of sexuality, where even basic health and safety information such as STI prevention is barricaded by dragnet-style filtering tools.  The online spaces once heralded as among the safest and most valuable for sex-positive publishers like sex bloggers, public health professionals, librarians, and relationship educators have become hostile to the free flow of information while governments from China to Australia to the United States censor the Internet and companies like Facebook, Amazon, and PayPal arbitrarily enforce vague Terms of Service policies.
    • In this far-reaching seminar, you'll learn the fundamentals of how to build anti-censorship techniques directly into your publishing process using nothing more technologically complex than copy-and-paste.  Whether you're a non-technical individual or a savvy multinational organization, you'll discover how you can put data portability, distributed publishing, and censorship circumvention tactics to use right away in order to stay one step ahead of those who would call you "obscene."

  9. (2012)  The ARRIStocrats: Cable Modem Lulz  - Chris Naegelin, Charlie Vedaa
    • The ARRIS TG852G is a DOCSIS 3.0 cable modem/router that's being deployed en masse by Time Warner and Comcast.  If you're a customer with this hardware, then you may be saddened to find that your service provider won't give you a login to configure the box.  This talk will walk you through two different methods to gain access to the device by exploiting weakly implemented authentication mechanisms on it.  You'll see how a three-year-old documented "feature" designed to keep customers out can quickly become a provider's worst security nightmare.  The talk will also go a step further and show you how aggregating some publicly available datasets would allow an attacker to use the vulnerability to quickly and effectively build an army of thousands of routers.
    • AI Transcript

  10. (2012)  The Autism Spectrum and You  - Mary Robison, Alex Plank, Jack Robison, Kirsten Lindsmith
    • As a kid, were you considered precocious?  Considered eccentric (or just plain weird) by other kids?  Have you ever thought that your sensory perceptions are different from other people?  Were you (are you still) the "little professor," intent on teaching everyone about your unique interest(s)?  Do you possess unusual interests?  Were you bullied?  Did you (do you still) live in your own world with restricted interests?  As a child, did you accumulate facts but not really understand them?  Do you often assume a literal meaning for metaphorical or ambiguous language?  Do you make naive or embarrassing remarks with surprising frequency?  Do you often fail to comprehend unspoken modes of communication?  Have special routines that cannot be altered?  Have unusual facial expressions, vocalizations, or posture?  Are you, in fact, bewildered by proper behavior?  Are you "face-blind" - unable to remember what the people you encounter every day look like, or to recognize them when you encounter them?  If you answer many or just some of these questions affirmatively, congratulations!
    • You, like many of your fellow attendees at HOPE, may have an alternate configuration for the wiring of your brain, now called an Autism Spectrum Disorder (it used to be called Asperger's Syndrome).  At HOPE, we're the majority; neurotypicals are the rest of the world that do not understand us and may even be afraid of us.  Most on the spectrum are male, but there are a lot of females flying under the radar.  This panel will discuss the spectrum and how we fit on it, and how we interact with the world at large.
    • AI Transcript

  11. (2012)  Brain Chemistry: How Psychoactive Chemicals Hack the Central Nervous System  - Jennifer Ortiz
    • People have been using chemistry to hack their bodies and their brains since antiquity.  In the past several decades, we have come to understand much more about the processes involved.  How is it that certain molecules cause profound alterations in perception?  How do they alleviate physical and psychological pain?  How do they get people high?  Why are some drugs psychoactive and not others?  Why are some toxic?  This presentation explores the answers to these questions and more.
    • AI Transcript

  12. (2012)  Building Radios to Talk to the Dead  - Wil Lindsay
    • Apophenia is the human ability to perceive patterns and meaning in completely random data sets.  The effect is often explored by "ghost hunters" who use electronic tools to find patterns in the environment around us and exploit them as a way to communicate with spirits of the deceased.  This discussion will cover the radio-based and electromagnetic technology commonly used for the reception of EVP or "Electronic Voice Phenomena."  These devices are often modified radios or home constructed circuits which follow a mixture of basic engineering, empirical results, metaphysical concepts, and, in some cases, pure hucksterism.  This talk will look at several of these devices, their underlying circuits, their design philosophy, and the culture that surrounds them.
    • AI Transcript

  13. (2012)  Cell Site Location Data and Nontrespassory Surveillance after U.S. v. Jones  - Hanni Fakhoury
    • With the rise of smartphones, the government's use of cell site location data to pinpoint our exact location has grown more widespread (and precise) over time.  For years, courts permitted the government to get this location data without a search warrant.  And judges that fought against the government's attempts at getting this data were met with an unfortunate reality of Fourth Amendment jurisprudence: we don't have any privacy in data we turn over to third parties, like cell phone providers.  The U.S. Supreme Court's recent decision in U.S. v. Jones however, presented a "sea change" in the law of warrantless surveillance, calling into question the future viability of the third-party doctrine.  This talk will review the law of location data, go in depth into how Jones calls this law into question, and conclude with the steps we need to take in the future in order to safeguard our privacy.
    • AI Transcript

  14. (2012)  Combat Robots Then and Now  - David Calkins, Simone Davalos
    • Fighting robots have been around since the first gearhead figured out that it was really fun to smash thousands of dollars worth of metal and electronics together in the name of sport.  This talk will cover the brief but intense history of combat robotics, how the technology has evolved, where it's going, and where combat robots happen around the world.  This presentation will include video, backstage photos, and insights from the organizers of the only large scale combat robot shows left in the United States: RoboGames and The ComBots Cup.
    • AI Transcript

  15. (2012)  Community Fabrication: Four Years Later  - Far McKon
    • One hacker's view of the last four years in 3D printing and the expansion of DIY culture.  It will cover the state-of-the-art then, the state of the art now, and where we imagine we will be in four years.  Far will review what technologies succeeded, what failed, and how 3D printing has grown, warts and all.  He'll also talk about the growth of hackerspaces in that time and how the changes in these topics tie together to show the growing pains of both hacker-centric movements.  He'll also make another round of predictions and discuss where 3D printing and hackerspaces are going next.
    • AI Transcript

  16. (2012)  Computer Forensics: Possibility, Probability, Opinion, and Fact  - Joe Cicero
    • How easy is it to end up with illegal content on your computer?  How expensive is it to prove you didn't know about it?  What is it like for someone who is arrested for a computer crime?  How long do these cases go on for?  What does the prosecution provide your attorney and forensic examiner with?  This presentation will cover these questions and more, based on experiences as a defense forensic expert.
    • AI Transcript

  17. (2012)  Countermeasures: Proactive Self-Defense Against Ubiquitous Surveillance  - Lisa Shay, Greg Conti
    • From governments fighting terrorists to companies hawking products to free online services where you are the product, it seems that everyone wants a piece of you and your personal information.  This talk begins with the current state of our surveillance society and delves deeply into countermeasures you and society at large can employ to maintain and protect your right to privacy.  Lisa and Greg will deconstruct a surveillance system and examine techniques for defeating or degrading each component.  They'll cover technical countermeasures, but also present techniques for influencing policy, law, and the incentives underpinning surveillance activities.  Left unconstrained, the problems of the emerging surveillance society will only get worse as more and more sensors and tracking applications invade the physical and digital worlds.  You'll leave this talk with a clear understanding of how to protect yourself and with strategies to deflect the trajectory of our surveilled future.
    • Slides
    • AI Transcript

  18. (2012)  Crimeware Tools and Techniques of 2012: Past, Present, and Future  - Alexander Heid
    • Much has evolved in the brief 24 months that have passed since the last presentation on this topic, which included a comprehensive overview of the Zeus and SpyEye Trojans, popular exploits being used in the wild, and cash out methodologies of the digital crime actors at the time.  Today, new digital currencies have emerged, vulnerabilities in popular crimeware kits have been made public, black market credit card trades have become automated, popular crime forums have been hacked and dumped, and the industry based around digital crime analysis and counterintelligence has grown exponentially.  In spite of recent arrests of a few individuals, malicious actors are still numerous and able to keep ahead of the law by adapting to the changing environment and hardening their operations.  This presentation will go over these developments, as well as the latest digital crime tools, techniques, and methodologies that are currently in use during the present day.  The talk will also assess where the current trends will be heading in the future.
    • AI Transcript

  19. (2012)  Cryptome Tracks the NYPD Ring of Steel  - Deborah Natsios, John Young
    • Cryptome's digital multimedia presentation of original cartography, animations, video, and architectural documentation will explore the urban implications of the NYPD One Police Plaza Security Plan - a.k.a. Ring of Steel - which locked down Lower Manhattan after 9/11, transforming its Civic Center into a threatscape centered on NYPD headquarters.  With its militarized jurisdiction mobilizing through technologies of command, control, communications, intelligence, surveillance, and reconnaissance, the Ring of Steel has declared itself an iconic public space for our time.
    • AI Transcript

  20. (2012)  DARPA Funding for Hackers, Hackerspaces, and Education: A Good Thing?  - Mitch Altman, Psytek, Willow Brugh, Fiacre O'Duinn, Matt Joyce
    • Mitch Altman caused a stir this spring when he publicly announced that he would not be helping U.S. Maker Faires this year, after it was publicly announced that they received funding from the Defense Advanced Research Projects Agency (DARPA).  So, what's the controversy?  DARPA, an agency of the U.S. military, has funded many famous projects over the past several decades, including GPS and the Internet.  People in DARPA are now making large amounts of grant funding available for hackers and hackerspaces to do projects of their choice, as well as funding for education through hands-on learning, which MAKE Magazine is using to help schools.  Does it matter that DARPA is responsible for the development of new technology for the U.S. military with an annual budget of $3.2 billion?  What are the ethics of using funds from people or organizations that may or may not be aligned with one's own goals?  What are the ramifications for the hacker/maker movement?  Is DARPA funding overall a good thing?  There is no simple answer.  Explore the ethics and ramifications with Mitch, as moderator, and the panelists, as they give their perspectives on this complex set of issues.
    • AI Transcript

  21. (2012)  Dead in a Pool of Blood and Millions of Dollars of Net Art  - Jeremiah Johnson (Nullsleep), Don Miller (NO CARRIER)
    • 0-Day Art is a warez group for art, focusing primarily on digitally represented works.  The project was born in response to situations where takedown notices, pay walls, and practices of "taking it offline" threaten the distribution and availability of art online.  0-Day Art seeks to put net art back on the net.  Using BitTorrent to package and distribute "art warez" within 24 hours of its initial availability, whenever possible, and social networks to quickly spread the word, the project has received attention from Today and Tomorrow, The Verge, GalleristNY, and ArtInfo, who referred to the project as, "the free-data pirates of the new media world."  This is just the start.  0-Day Art exists at the intersection of art critique, hacktivism, and open culture, and manifests itself in many different ways.  This talk will cover the history of 0-Day Art, as well as a brief history of "The Scene" (warez, demo, and art).  Past projects, current projects and challenges, and the future of 0-Day Art will be discussed.
    • AI Transcript

  22. (2012)  Declassifying Government and Undermining a Culture of Insecurity  - Ivan Greenberg
    • It is critically important to obtain and publicize declassified government intelligence documents in order to demystify official narratives of domestic security.  Over the last decade, Ivan received about 60 FBI files by using the Freedom of Information Act and by initiating a lawsuit, while writing two books on civil liberties and surveillance.  He will discuss his experiences getting government documents and show how new information about surveillance practices can help the American people make better informed judgments about how surveillance systems are developed and deployed.  Is it possible for popular democratic participation in the operation of surveillance systems?  Whose security is really at stake?  How can we counter the creation of a top-down, official "culture of insecurity?"
    • AI Transcript

  23. (2012)  Designing Free Hardware: Scratching Your Own Itch with a Soldering Iron  - Matthew O'Gorman, Tim Heath (crashcart)
    • So you have played with free and open-source software?  Time for things to get real.  Learn how to go from a simple idea like "I need some electronic dice" or "wouldn't it be insanely great if I could control my TV from my phone" to a simple breadboard prototype, on to a custom schematic and then laid out in PCB, sending your Gerber files to China for fabrication, and then carefully soldering it together to scream "it's alive" as your LED glows brightly for the first time.
    • AI Transcript

  24. (2012)  Destroying Evidence Before It's Evidence  - Hanni Fakhoury
    • Covering your tracks out of fear of getting caught with your hands in the digital cookie jar can sometimes get you in more trouble than whatever crime the feds think you may have committed in the first place.  This presentation identifies three specific scenarios where the act of trying to cover your digital footprints - oftentimes in innocuous and legal ways - can get you into trouble: the nebulous crime of "anticipatory obstruction of justice," which can cover something as mundane as deleting an email before you're even suspected of committing (let alone charged with) a crime; the ever-expanding Computer Fraud and Abuse Act, which has been stretched to cover things that are neither fraudulent nor abusive; and the potential problems with encryption.  The presentation will conclude with some ways you can protect yourself that can help minimize claims that you obstructed justice.
    • AI Transcript

  25. (2012)  Digital Security in Health Care Institutions  - Jorge Cortell, Alvaro Gonzalez
    • Health care institutions usually have a large number of digital devices, networks, and databases.  Lots of data goes through them, but are you aware of how much data that is?  And how secure is it?  How easily can this data be captured?  How easy is it to access those medical devices?  Can this be done without being detected?  After six years of involvement in health care IT projects, Jorge and Alvaro have some stories and details to share.
    • AI Transcript

  26. (2012)  DKIM: You're Doing It Wrong  - Quincy Robertson
    • DomainKeys Identified Mail (DKIM) is the most effective, widely deployed email forgery countermeasure available today... if implemented correctly.  Many of the world's largest and most trusted companies, including some of those driving the standard, have fatally flawed deployments.  When the first standard for SMTP was published in 1982, the Internet was a much smaller and safer place.  Ever since the first spammers, we've been trying to fix email with various hacks such as callout verification, forward confirmed reverse DNS, PGP, S/MIME, SPF, Sender ID, DomainKeys, DKIM, and an ever-changing collection of filters.  All of them have serious flaws.  This talk will cover several common mistakes made when deploying DKIM and how they can be exploited to achieve the holy grail of email forgery.
    • DKIMPWN
    • AI Transcript

  27. (2012)  DUI/DWI Testing - A Hacker's View of the Technology and Process Behind the BAC and Standard Field Sobriety Test  - WJ, Alexander Muentz
    • This talk will look behind the process, techniques, and technology (or lack thereof) used by law enforcement to identify suspected intoxication.  What most people don't know is that there is little in the way of scientific process or technology that is used during the testing of intoxication.  The process relies on a strategy of behavioral cues and coercion often geared towards leading an individual to admit wrongdoing.  The technology and instruments used by law enforcement for determining sobriety has changed little over the years.  Some of these technologies are inherently flawed or misleading.  This presentation will take a closer look at the most common techniques and equipment including the Breathalyzer, Horizontal Gaze Nystagmus (HGN), and the instruction led Standardized Field Sobriety Test (SFST).  There will be a discussion of how each of these processes works and an enumeration of potential flaws or tactics one should be aware of to ensure fair and unbiased treatment.
    • AI Transcript

  28. (2012)  Electric Bodies and Possible Worlds  - Jaime Magiera, Micha Cardenas, Cayden Mak
    • Though there are many expensive, mainstream solutions for wearable computing, augmented/virtual reality, and alternate reality gaming, there is also a burgeoning community of DIY projects in these areas that focus on self-expression, empowerment, and community building.  This panel will provide an overview of several important projects for wearable computing, augmented/virtual reality, and alternate reality gaming.  In particular, the session will relate how these projects allow individuals to explore the many possible worlds and identities available to us.
    • AI Transcript

  29. (2012)  The Emergence of Hacker as Artist and Artist as Hacker  - Andrew Cameron Zahn, Katherine Bennett, William Cromar, Chris Thompson
    • The new direction and emergence of hackers working like artists and artists working like hackers brings up a wealth of questions pertaining to these new mediums.  How do the practices of "hackers" differ, if at all, from those of "artists?"  Should we question when or how a hacker project falls between the lines of art, design, or hacking?  The panel will discuss how their work bridges the gap between hacking, new media, and art.  Their skills and interests vary quite a lot, but they all use technology to make a statement.
    • AI Transcript

  30. (2012)  Exploiting Zigbee and the Internet of Things  - Travis Goodspeed
    • Now that Zigbee is finally appearing in the wild, Travis will take a look back at all the nifty ways of exploiting it.  (Zigbee is a low-cost, low-power, wireless mesh network standard.)  This fast-paced lecture features as many practical, real-world exploits as can fit in the time slot.  Learn how to extract firmware from a locked Freescale MC13224 by grounding pin 133, how to extract keys from a Chipcon CC2530 by erasing it first, and how to hijack control of other radios with a few hypodermic syringes.  You'll also learn how Certicom's proprietary crypto library caused multiple Zigbee Smart Energy Profile stacks to remotely expose private ECC keys and why none of this matters because cleartext traffic is easily found in most major cities.
    • AI Transcript

  31. (2012)  Explosive Steganography  - Eric Davisson (XlogicX)  
    • Encryption makes information secret, steganography hides the information in plain sight.  We fancy hiding it in a "pile" that most people would avoid.  This talk explores hiding steganography in mediums such as archive exploders, file carving exploders, and virus files.  There will be a release of the open-source tools eZIPlode/asour, magicbomb/-asour and hivasour/hivsneeze.
    • Tools and Presentation
    • AI Transcript

  32. (2012)  Geeks and Depression  - Robin DeBates, Mitch Altman, Meredith L. Patterson, Jimmie Rodgers, Daravinne
    • Many of us in the geek community suffer greatly from serious depression.  Enough so that several notable hackers have committed suicide over the past couple of years, including the 22-year-old co-founder of Diaspora.  Moderated by Robin, a professional geek therapist, the panelists in this session will share their personal histories with depression in hopes of showing that none of us in the geek world need to be isolated with our feelings of being alone, depressed, or suicidal.  Is it O.K. to talk about depression and suicide in the hacker community?  This panel thinks it is important to make it so.
    • AI Transcript

  33. (2012)  Hackers and Media Hype or Big Hacks That Never Really Happened  - Space Rogue  
    • Media will often report "hacks" that either never actually happened or have extremely flimsy evidence.  They then become major news stories through media hype while the reality is seldom reported at the same level.  This talk will closely examine several instances of such stories and compare the hype with the reality.  Examples will include Kevin Mitnick's compromise of NORAD, the use of steganography by al Qaeda, the electrical blackout in Brazil, the failure of a water pump in Illinois, and others.  Close attention will be paid to the media's role in presenting these stories and how they morphed from purely circumstantial to quoted facts.  The structure of a hyped story will be examined so that it can be easily identified and methods of combating the hype will be discussed.
    • Slides
    • AI Transcript

  34. (2012)  Hacking Mindsets: Conceptual Approaches to Transmission Art, Improvisation, Circuitbending, and Gaming Technology  - Tamara Yadao, Nicole Carroll, Joshua Kopstein
    • In Richard Stallman's "On Hacking" from 2000, he addresses the stigma attached to the notion of "hacker," while clarifying the act of hacking as a creative mindset that encourages playful/clever exploration of established cultural forms, from eating utensils to practical jokes, as opposed to methods for security breach.  Beyond the more obvious examples of hacking, Stallman applies this mindset to two specific music compositions: "Ma Fin Est Mon Commencement" by 14th century French composer Guillaume de Machaut and "4'33" by 20th century American avant-garde composer John Cage.  The former is a palindromic music composition important to the development of polyphonic music and the latter is a composition written without musical notes.  By referring to these two innovations as hacks more then music compositions, Stallman makes a cultural connection between hackers and artists - that hacking is innately creative.  This presentation/demonstration will examine the notion of hacking and its connections to composer John Cage, music improvisation, and re-purposed instrumentation including radios and transmitters as instruments, circuitbent instruments, and the DIY aspect of software and hardware instruments in the demo and chip music scenes.
    • AI Transcript

  35. (2012)  Hacking the Cosmos via Crowdsourced Particle Astronomy  - Ray H. O'Neal, Jr.
    • The Cosmic Cube is a proposed "desktop" astroparticle or cosmic ray detector enabling ad-hoc formation of cosmic ray telescopes between cube operators.  The speaker will address the use of peer-to-peer networks of detectors for investigating the nature of the flux of high energy cosmic rays and how the random nature of detection events might also be applied to information security.
    • AI Transcript

  36. (2012)  Hacking the Spaces  - Johannes Grenzfurthner, Sean Bonner
    • In 2009, Johannes and Frank Apunkt Schneider published their critical pamphlet "Hacking the Spaces," causing a shitstorm in forums and mailing lists.  The publication of the text on BoingBoing was even called a "PR disaster for the hackerspaces movement" by various members of the scene.  Three years later, the discussion is still raging.  Are hackerspaces the inclusionist paradises that their members want them to be, or are they just White middle-class boys' clubs generating nothing more than a few more streamlined members of "Generation Self-Exploitation?"  This talk is an invitation to look at the debate and analyze its potential and drama.  We promise dramatic potential and the potentially dramatic!
    • AI Transcript

  37. (2012)  Hack the Law  - Brendan O'Connor
    • Recent bills such as ACTA, COICA, and SOPA in legislatures worldwide demonstrate that there exists a fundamental disconnect between hackers and politicians.  Worse, the people charged with dealing with law on the ground, the lawyers, rarely have any significant technical background obtained within the last few decades.  This must change.  It's all well and good to write your congressperson or donate to the EFF, but it's not enough; we need hackers to go to law school.  Lawyers - whether they work as attorneys, or bring their knowledge of the law back to other fields - are uniquely situated to effect direct change on politics, social issues, and the law on the ground (where they arrest poor hackers) and, unlike many fields, it's not enough to be self-taught.  This presentation will focus on the utility of the hacking ethos within the law, as well as the "law school experience," technical bits about actually getting in, and how to keep yourself from going nuts while spending three years surrounded by those who can't tell their megabytes from their overbites (and are terrified by Wireshark, let alone the more subtle tools in existence).  Expect stories, humorous anecdotes, and terrifying lapses in judgment.
    • AI Transcript

  38. (2012)  Hacktivism, Tools, and the Arab Spring  - Peter Fein, Meredith L. Patterson, The Doctor
    • During the Arab Spring of 2011, agents of Telecomix, members of Anonymous, and a multitude of independent hackers took direct action to aid dissidents by helping to circumvent censorship, disseminating photographs and video footage of violence against peaceful protesters, redeploying dial-up modem pools, and using DNS hijacking to warn people of online surveillance.  During this time, some interesting discoveries were made by Telecomix, namely, man in the middle attacks with forged SSL certificates and the installation of deep packet inspection hardware in the networks of a number of Syrian ISPs for the purpose of Internet censorship.  The activists used logs from Blue Coat web gateway devices to reverse engineer the rulesets Syrian authorities were using, so as to better advise protesters on methods of evasion.  Telecomix was also instrumental in tracing where the Blue Coat DPI devices were sourced from and how they were delivered to Syria in violation of United States export regulations.  The presenters (all agents of Telecomix) were among those active during the Arab Spring, and will discuss what surveillance measures they encountered, some of the threats against protesters in Syria and Egypt, and how strategies for supporting protesters evolved in response to the changing situation on the ground.
    • AI Transcript

  39. (2012)  HIDIOUS Methods of Keystroke Injection  - JP Dunning
    • It's amazing what can be accomplished with just a few keystrokes.  Changing user passwords, formatting disks, and scanning a network are each one command away in most modern operating systems.  What if you had two minutes of access on a system?  Is this enough time to accomplish information gathering or exploitation on even the most hardened system?  It just might be.  Through a combination of software and hardware, hundreds of keystrokes a minute can be flawlessly injected into any computer to gain control of system resources.  The HIDIOUS (HID Injection Over USB Suite) allows for easy configuration of keyboard/mouse injection attacks through USB.
    • AI Transcript

  40. (2012)  Historic Hacks in Portable Computing  - Bill Degnan, Evan Koblentz
    • "Portable" computing began with handheld calculating aides such as the abacus and slide rule, continued in the 1950s with mainframes mounted inside Army trucks, and emerged in suitcases, briefcases, and even pockets in the 1970s.  All throughout this rich history, there were clever, funny, and security-themed hacks involved.  In some cases, there were hacks needed just to construct the systems, and in others there were hacks in system usage.  This talk will explain a dozen examples from which modern hackers can learn.
    • AI Transcript

  41. (2012)  Hosting irc.2600.net - My Life with the Thrill Kill Cult  - Andrew Strutt (r0d3nt)
    • An overview of the history of 2600net for at least the last ten years.  This talk will cover 2600net infrastructure and policies, why it is the way it is, along with how to communicate securely and build trust with users and friends.  Who are the hosts and operators?  Meet the crew!  What other communities are around $2600 and the IRC network?  How can you get involved?  Special attention will be given to DDoSes, LulzSec, Anonymous, th3j35t3r syndrome, and all sorts of other challenges.  Expect other staffers and channel operators to stop in for this talk.
    • AI Transcript

  42. (2012)  How to Communicate with Your Car's Network  - Robert Leale
    • Modern vehicles are essentially mobile computers and controller networks.  On average, there are around ten embedded controllers in a vehicle.  These controllers are responsible for running the engine, locking and unlocking the vehicle, sounding the horn, and much, much more.  These networks are very different from current computer networks.  This talk will help you understand how to get started, what information is on the vehicle network, and how you can use this data to get information from and send commands to these controllers.  Additionally, this talk will list the current tools available for communicating with vehicles and how to interpret the communications between the controllers.
    • AI Transcript

  43. (2012)  How to Retrofit the First Law of Robotics  - Eben Moglen
    • We live with robots now, as we always knew we would.  But they have no hands or feet.  We carry them in our pockets.  They see what we see.  They hear what we hear.  They always know where we are.  But they do not work for us, and they are not programmed to obey the First Law.  Profit made them, profit runs them, and they hurt us every day.  Free Software can retrofit the First Law of Robotics into the robots we call cell phones, but those who control the robots don't want freedom inside.  That's where we come in.  This talk will discuss how.
    • AI Transcript

  44. (2012)  ICANN's New gTLD Program: Implications on Security, Stability, and Governance  - Alexander Urbelis
    • The Internet is about to rapidly expand.  Through ICANN's new Generic Top-Level Domain (gTLD) program - for the first time ever - individual entities can customize the space to the right of the dot.  While currently only 22 gTLDs exist (e.g., .com, .net, .org, etc.), on June 13, ICANN announced that it had received an unexpected 1,930 applications for new gTLDs, ranging from applications for .AARP to .ZULU.  This talk will examine the security and stability concerns that arise from the rapid expansion of the Internet's root zone.  Also included will be the current state of the new gTLD program, the security issues that plagued the application process in April, and how this new model of gTLD ownership (with large swaths of Internet real estate in the hands of private entities) will change our current model of Internet governance.
    • AI Transcript

  45. (2012)  I'm Not a Real Friend, But I Play One on the Internet  - Tim Hwang
    • This talk examines the topic of socialbots - realistic, automated bot identities online that are optimized to reliably elicit certain types of social behaviors in groups of users on platforms like Facebook and Twitter.  Deployed en masse, large swarms of these bots are able to subtly (and not-so-subtly) shape the ways in which communities grow, connect, and behave on these platforms.  Insofar as people increasingly come to rely on these networks into the future, the bots hold the promise (and threat) of shaping not only the social universe of opinions and influence, but real world coordination and action among people as well.  Ultimately, this talk will conclude by discussing how these bots suggest the evolution of classic social engineering into a broader social hacking - which approaches human networks as if they were computer networks and applies similar principles for their compromise and defense against the social influence of third parties.
    • AI Transcript

  46. (2012)  Information Distribution in the Arab Spring - No Hacks Required  - Griffin Boyce
    • From pirate radio, livestreaming, and video-sharing apps, to asynchronous mesh networks, Bluetooth, SMS/MMS, I2P, and Tor hidden services, the ways that activists in the Middle East and North Africa get critical information out are far more varied than most people know.  With so much attention given to leaks recently, it's easy to perceive the "liberation" of information as involving major hacks of critical systems.  But reality is, as always, much more complex and interesting.  This talk will show just how distribution channels in the Middle East are created and maintained, and the positive impacts they can have.
    • AI Transcript

  47. (2012)  Infrastructure Mediated Sensing of Whole-Home Human Activity  - John McNabb
    • Devices are being developed to monitor what you do in your home.  Even without Orwell's telescreen (which is under development), there is a lot of information that can be collected about your Activities of Daily Life.  The beneficial goals of these devices include promoting positive things like water conservation, helping people improve their personal health, and monitoring people in assisted living environments.  This talk will describe the technology of the devices used to collect and transmit this data, and discuss some of the social, ethical, political, economic, privacy, and legal issues raised.  What could go wrong?  Could these systems be used by governments to micromanage personal behavior?  Could employers use these systems to regulate employees' off-duty behavior?  Could such data be used to convict people in court?  Could this data be stolen, abused, or falsified?  The answer for each of these questions is "yes."
    • AI Transcript

  48. (2012)  The Internet is for Porn!  How High Heels and Fishnet Have Driven Internet Innovation and Information Security  - Chris Kubecka
    • A dark and seedy journey to explain the real driver behind Internet innovation: porn.  How an economy built on the ultimate satisfaction just a click away has driven technological advances.  Racy browsing habits involving our innermost secrets, vulnerable parties, and criminal syndicates have driven malicious code and subsequent security advances.  Broad ranging censorship involving much more than pornography has been the end result in attempts to reign in such "unhealthy" habits by well-intentioned governments and organizations.  This talk will include a timeline of pornography on the Internet, related security threats, an overview of industry economics (legal and illegal), and related censorship.  Audience discussion and participation is welcome, but please, no BYOP.
    • AI Transcript

  49. (2012)  IPv6 Now!  What Does This Mean?  - Joe Klein
    • On June 6th, World IPv6 Launch Day occurred, another step in the replacement of the aging IPv4 Internet.  Adoption of IPv6 as of June 17th is 6.9 percent in Romania, 4.5 percent in France, 1.4 percent in Japan, 1 percent in the United States, 0.58 percent in China, and 0.28 percent in Russia.  This is up from less than 0.006 percent within the past two years.  This presentation will answer the questions: "What is the risk of adopting IPv6?", "What is the risk of not adopting IPv6?", and "What are the new opportunities for hackers?"
    • AI Transcript

  50. (2012)  Jason Scott's Strange and Wonderful Digital History Argosy  - Jason Scott (Jason Sadofsky)
    • With a few small seeds of facts, digital and computer historian Jason Scott will draw together a multi-medium presentation of events, terms, facts, and references to set you off on a journey of learning for the rest of the year.  Combining material from his three in-production documentaries and years of research, attendees will be given the threads that pull massive airships of knowledge out of the sky and into your minds.  Formal attire welcome but not mandatory - participation encouraged - paradigms blown - mysteries solved.
    • AI Transcript

  51. (2012)  William Binney Keynote  - William Binney
  52. (2012)  The Yes Men Keynote  - The Yes Men (Mike Bonanno and Andy Bichlbaum)
  53. (2012)  "Kill the Internet"  - MemeFactory (Mike Rugnetta, Stephen Bruckert, Patrick Davison)
    • As grassroots Internet culture grows and flourishes, pushing out into international mainstream recognition, top-down cultural models are threatened and fight back, while governments attempt to quash and chill dissent empowered and organized by the Internet.  How are people from the Internet fighting back?  What does that even mean?  And will it be enough?
    • MemeFactory is three guys that give tightly rehearsed performative lectures about Internet culture.  Their talks document, explore, and critique the emerging culture of the Internet in a visually-focused, fast-paced style that mimics the experience of having ten browser windows open while talking on the phone and watching a YouTube video.
    • AI Transcript

  54. (2012)  Legal Processes as Infrastructure Attacks  - Alexander Muentz
    • Law enforcement and lawmakers have been showing much more of an interest in regulating the Internet.  The hacker community needs to understand how certain legal methods work like IT infrastructure attacks.  This talk will explain legal processes such as subpoenas, search warrants, and e-discovery as IT infrastructure attacks, as well as how to talk to lawyers.  This is an evolving topic as the environment has been constantly changing and, of course, has become more complicated.  Also included: a discussion on the recent Megaupload and other domain seizures, forced IP and search engine blocking, and a question and answer session on related matters.
    • AI Transcript

  55. (2012)  Make Your Laws: Practical Liquid Democracy  - Sai
    • This talk will include background on the concepts of direct, representative, and liquid democracies; the tradeoffs inherent in different types of government; interesting problems for online voting and policy authorship; examples of similar systems in different countries; discussion of some legal context (e.g. electronic signatures and the democratized use of Super PACs); a practical road map to gaining full control over your legislature; and Q&A.  Make Your Laws (makeyourlaws.org) is an open-source, nonprofit, practical project that aims to replace all existing legislatures with online liquid democracies.  The aim is simple: to let you make your laws.
    • AI Transcript

  56. (2012)  Manufacturing Modern Computer Chips  - QueueTard (Todd Fernandez)
    • Modern computer chips are using transistors with features as small as 22nm.  They are produced in factories that are 10,000 times cleaner than an operating room that can think like Skynet.  Combined, the chips they produce run everything from your cell phone to the Internet itself.  While outsiders might see it as the realm of multi-billion dollar corporations, in reality, it has been achieved through a hardcore application of the hacker mindset.  Each new advancement involves hacking the theories of electrical engineering, hacking waves of light, and sometimes hacking physics.  This talk will go over how and why the design of a modern nanoscale transistor was developed, as well as discuss the processes used to build them, and the incredible equipment that makes it all possible.  Plus some fun stories about what goes wrong.
    • Slides
    • AI Transcript

  57. (2012)  Mastering Master-Keyed Systems  - Deviant Ollam, Babak Javadi
    • The world of locks is one in which, so very often, things old become new again.  Master-keyed lock systems fall into this category.  For years now, many people have shared advice and stories regarding methods of attacking master-keyed systems.  This year, at HOPE Number Nine, The Open Organisation Of Lockpickers will be running a contest in which attendees may attempt to decode a master-keyed system during the weekend.  If you stop by this presentation, you'll be a few steps ahead of everyone else who is attempting this interesting and different lockpicking game at HOPE Number Nine - and you'll learn about how master-keyed systems are often vulnerable to many surreptitious attacks.
    • AI Transcript

  58. (2012)  Messing with Nmap Through Smoke and Mirrors  - Dan Petro (AltF4)
    • Reconnaissance on a network has been an attacker's game for far too long.  Where's the defense?  Nmap routinely evades firewalls, traverses NATs, bypasses signature-based NIDS, and gathers up the details of your highly vulnerable box serving Top Secret documents.  Why make it so easy?  This talk will explore how to prevent network reconnaissance by using Honeyd to flood your network with low-fidelity honeypots.  Dan will then discuss how this lets us constrain the problem of detecting reconnaissance such that a machine learning algorithm can be effectively applied.  (No signatures!)  Some important additions to Honeyd will also be discussed along with a live demonstration of Nova, a free software tool for doing all of the above.
    • AI Transcript

  59. (2012)  "No Natural Resources Were Hurt Assembling This Sofa"  - Per Sjöborg
    • This talk is an introduction and overview of a new and exciting field in robotics called Self-Reconfiguring Modular Robotics (SRCMR).  SRCMR is basically about modules, like LEGO pieces, that can assemble themselves into anything you want (self-reconfigure).  You will hear how this makes a prosperous, growing, and environmentally friendly world accessible for all of us.  This is possible because the stuff you need is assembled from the same modules, again and again, using no resources other than small amounts of energy.  This drastically reduces the resources we use, and de-couples growth and environmental problems.  Because the modules are programmable, SRCMR will also make the world completely hackable, introducing many interesting opportunities and challenges.
    • AI Transcript

  60. (2012)  Nymwars: Fighting for Anonymity and Pseudonymity on the Internet  - Eva Galperin
    • The last year has seen an Internet-wide debate over real names, pseudonyms, and anonymity online, especially on social networks and in the comment sections of blogs and newspapers.  Facebook has required users to use their real names from the very beginning and newspapers have increasingly embraced the same requirement for commenting on their websites.  Proponents of real name policies cite increased civility and quality of content.  But pseudonymity and anonymity have a long history in public discourse, and they are essential for privacy and speaking truth to power.  This talk will examine the debate over anonymity and pseudonymity online, with a focus on Facebook and the Arab Spring, and Google Plus and nymwars.
    • AI Transcript

  61. (2012)  Occupy the Airwaves: Tools to Empower Community Radio Stations  - Maggie Avener, Ana Martina
    • The Prometheus Radio Project started with radio pirates fighting for local groups to be able to run community radio stations.  Prometheus builds, supports, and advocates for community radio stations which empower participatory community voices and movements for social change.  They are currently creating a number of tools to support community groups as they prepare for an upcoming once-in-a-lifetime chance to apply for low power radio licenses.  RadioSpark is an online hub where applicants, engineers, lawyers, and other supporters can exchange knowledge and plan together.  RFree is free and open-source software that applicants can use to find available channels and prepare their FCC applications.
    • AI Transcript

  62. (2012)  Old-School Phreaking  - Cheshire Catalyst, John Draper, Tom Santa Monica
    • Members of the old-school will regale the assembled throngs with tales of "The Golden Age of Phone Phreaking."  Those were the days of in-band signaling when anyone who could put out a tone of 2600 hertz could control the "Long Lines" network.
    • AI Transcript

  63. (2012)  The Open Secure Telephony Network  - Lee Azzarello, Mark Belinsky
    • All of the necessary technologies and communications standards exist today for voice communications that are as secure as OpenPGP email.  Both proprietary and open-source solutions exist for desktop and mobile devices that implement the necessary bits to provide a solution without dependence upon one global service provider.  ostel.me provides both a service and an application for the Android OS that is only marginally more complex to use than dialing an existing phone number, while still based entirely on open standards like SIP and ZRTP.  The app is experimental and is based on existing open-source client code provided by the CSipSimple, pjsip, and zrtp4pj projects.
    • Open-{Secure,Source,Standards} Telephony Network
    • AI Transcript

  64. (2012)  The Original WWII Hackers  - George Keller
    • A look at some of the history of code breakers in the second World War.  Bletchley Park in the United Kingdom was the home of the original WWII "hackers" and George will describe what goes on there today, as well as what Navy cryptologists managed to achieve during the war.
    • AI Transcript

  65. (2012)  Patents: How to Get Them and How to Beat Them  - Ed Ryan
    • Patents are a distasteful reality for hackers, open-source programmers, and entrepreneurs alike.  This talk aims to provide a working knowledge of how to read a patent, what is required to obtain patent protection, and how to defend yourself against patent lawsuits.  This talk is an academic discussion of patent law and should not be construed as legal advice.
    • AI Transcript

  66. (2012)  Phone Phreak Confidential: The Backstory of the History of Phone Phreaking  - Phil Lapsley
    • Five years in the making, Phil has finally finished Phone Phreaks, his book on the history of phone phreaking from the 1950s to the 1980s.  In this talk, he will weave together the evolution of phone phreaking with the backstory of the writing of his book.  From giving John "Cap'n Crunch" Draper a piggyback ride around his apartment in order to secure an interview, to cleaning out Joybubbles's apartment after his untimely demise, Phil's research took him through the maze of twisty little passages that wind through the history of this underground hobby.  Some of the characters you'll meet include the phone phreak CEO of an electronic warfare company, a cell of Stony Brook students busted for Blue Boxing, and the mysterious and cantankerous head of the International Society of Telephone Enthusiasts.  You'll also get a behind the scenes tour of the NSA and FBI's phone phreak files and the 400 Freedom of Information Act requests necessary to get them into the light of day.
    • AI Transcript

  67. (2012)  Practical Insecurity in Encrypted Radio  - Sandy Clark, Matt Blaze, Perry Metzger
    • APCO Project 25 ("P25") is a suite of wireless communications protocols used in the United States and elsewhere for public safety two-way (voice) radio systems.  The protocols include security options in which voice and data traffic can be cryptographically protected from eavesdropping.  This talk analyzes the security of P25 systems against passive and active adversaries.  The panel found a number of protocol, implementation, and user interface weaknesses that routinely leak information to a passive eavesdropper or that permit highly efficient and difficult to detect active attacks.  They found new "selective subframe jamming" attacks against P25, in which an active attacker with very modest resources can prevent specific kinds of traffic (such as encrypted messages) from being received, while emitting only a small fraction of the aggregate power of the legitimate transmitter.  And, more significantly, they found that even passive attacks represent a serious immediate threat.  In an over-the-air analysis conducted over a two year period in several U.S. metropolitan areas, they found that a significant fraction of the "encrypted" P25 tactical radio traffic sent by federal law enforcement surveillance operatives is actually sent in the clear - in spite of their users' belief that they are encrypted - and often reveals such sensitive data as the names of informants in criminal investigations.
    • Aside from being important practical vulnerabilities in their own right, the problems in P25 secure radio represent an example of a class of problem that the security and cryptography community has largely ignored.  Radio protocols typically do not fit the negotiated two-way communication model under which most security protocols are designed (and to which our community devotes most of its attention).  One-way protocols, like P25, in which there is no negotiation or exchange between the transmitter and the receiver are actually rather unusual, and relatively little is known (or written in the literature) about robust design principles for them.  In this talk, new approaches to protocol design will be suggested that might allow us to do better.
    • AI Transcript

  68. (2012)  Printable Electronics and the Future of Open-Hardware  - John Sarik
    • Many open-hardware projects use Integrated Circuits (ICs), but these ICs are literal black boxes because the manufacturers do not provide the silicon source code.  There's also no way for makers to cost effectively modify and recompile this source code to fabricate custom ICs.  But there is hope!  Printable electronics based on novel materials and low-cost fabrication techniques have the potential to enable open-hardware at a whole new level.  This talk will provide an overview of current printable electronics technology and discuss the issues that will arise as open-hardware moves beyond silicon.  What happens to open-hardware when you can download and print an entire electronics project?  How can we ensure that the materials used are open, widely available, and safe?  How can we make IC design accessible to non-engineers?  What should a Thingiverse for printable electronics look like?  What are the legal issues surrounding printable electronics?
    • AI Transcript

  69. (2012)  Privacy - A Postmortem (or Cell Phones, GPS, Drones, Persistent Dataveillance, Big Data, Smart Cameras and Facial Recognition, The Internet of Things, and Government Data Centers Vacuuming Google and Facebook, Oh My!) - Part 1  - Steven Rambam (Steve Rombom)
    • Privacy - A Postmortem... - Part 2
    • With a few keystrokes, it is now possible for an investigator to determine a target's location, activities, finances, sexual orientation, religion, politics, habits, hobbies, friends, family, their entire personal and professional histories... even accurately predict what they will do and where they will go in the future.  Without leaving the office, a government agent can surveil a subject and "watch" their activities 24/7/365: where they drive, when they walk down the street, if they attend a church or synagogue or mosque or a demonstration or visit an abortion clinic or a "known criminal activity location" or meet with a "targeted person" or a disliked political activist.  There is no longer any place to hide.
    • Since the very first HOPE conference, private investigator extraordinaire Steven Rambam's lectures on privacy have kept attendees ten years ahead of the curve regarding surveillance technologies, investigative techniques, and the assaults upon personal privacy by government's Big Brothers and private industry's even bigger Big Sisters.  His lectures described cell phone "pinging" eight years before it was used by the FBI and "Google Glasses" four years before they were announced.  The past two years have seen the largest expansion of surveillance technologies ever and, in a wide ranging three hour lecture packed as always with dozens of real-world examples and case studies, Steven will provide a terrifying update on our absolute loss of privacy.  His lecture is not for the weak of heart - or for those afraid of drones.
    • AI Transcript

  70. (2012)  Privacy by Design - a Dream for a Telecommunications Provider That Uses Strong Cryptography to Ensure Your Privacy  - Nick Merrill
    • This is a talk about launching a nonprofit organization that has some unique and disruptive ideas which challenge some of the basic assumptions about how modern communications systems work and that have the potential to transform the telecommunications and ISP industries with regards to privacy and freedom of expression.  The seemingly dueling concerns of cybersecurity and privacy can both be addressed to some degree by the promotion of ubiquitous and opportunistic encryption, which would allow for an important political consensus between parties interested in either of those two issues.  This topic and content is relevant to the hacker community and to HOPE attendees because of the implications of dragnet surveillance that has become commonplace in recent years, fueled in part by advances in technology and due to a shift towards more and more communication happening in the digital domain.
    • AI Transcript

  71. (2012)  Privacy Tricks for Activist Web Developers  - Micah Lee
    • Do you care about the privacy of your website's visitors, but also depend on social media to get your message out?  Do you want to protect your visitors' anonymity in case you or a third-party service you use gets subpoenaed?  Do you want to be able to get meaningful and pretty analytics without third-parties tracking your visitors?  Can some kid in a coffee shop really hijack your users' accounts that easily?  Chances are Google, Facebook, and Twitter know as much about your website's visitors as you do, IP addresses and user agents are sprinkled about your server's filesystem, Google Analytics is watching everyone's every move, and some kid in a coffee shop is already pwning your users.  But it doesn't have to be this way!  This technical talk will cover tricks that web developers and sysadmins can use to minimize the privacy problems that plague the modern web.
    • AI Transcript

  72. (2012)  Project Byzantium: An Ad-Hoc Wireless Mesh Network for the Zombie Apocalypse  - The Doctor, Haxwithaxe, Sitwon
    • Project Byzantium (a working group of HacDC) is proud to announce the release of Byzantium Linux, a live distribution which makes it fast and easy to build ad-hoc wireless mesh networks.  Due to the actions of certain governments (such as those of Egypt, Tunisia, and Syria), alternative data networks are becoming more and more important as a means to communicate, organize, and coordinate.  Project Byzantium aims to help support (and in some cases, replace) damaged or compromised Internet infrastructure and services with commodity Wi-Fi-enabled equipment and a flexible, improvisable architecture.  The presenters will discuss some of the engineering challenges faced and solutions that were developed to overcome them, including automatic network configuration and interaction with mobile clients that have limited capabilities.
    • AI Transcript

  73. (2012)  Protecting Your Data from the Cops  - Marcia Hofmann
    • What should you do if the police show up at your door to seize your computer?  If they ask for passwords or passphrases, do you have to turn them over?  Can they search your phone if they arrest you during a protest?  What about when you're crossing the border?  Your computer, phone, and other digital devices hold vast amounts of sensitive data that's worth protecting from prying eyes - including the government's.  The Constitution protects you from unreasonable government searches and seizures, but how does this work in the real world?  This talk with help you understand your rights when officers try to search the data stored on your digital devices, or keep it for further examination somewhere else.  The constitutional protections that you have in these situations, and what their limits are will be discussed, along with technical measures you can take to protect the data on your devices.
    • AI Transcript

  74. (2012)  Pwn the Drones: A Survey of UAV Hacks and Exploits  - Trevor Timm, Parker Higgins
    • Drones are no longer a scary possible future of surveillance and remote force - they're here.  Internationally, drones are being deployed for military action and observation.  At home, police departments, border patrols, and others are acquiring UAVs and developing programs to fly them; there's even talk about adding "less lethal" arms to these domestic drones.  Think TASERs and rubber bullets shot from the sky.  But a series of alarming events over the past few years have demonstrated that many of these unmanned vehicles are dangerously vulnerable to exploits, leading to intercepted data, flight failures, and even remote takeovers.  In this talk, Parker and Trevor will explain the privacy and security implications of some of the most sensational drone exploits and the weaknesses that enabled them.  They'll also go over the work of communities and individuals that have been hacking drones from scratch, and what their efforts mean for our future understanding and regulation of drones.
    • AI Transcript

  75.   Real Advances in Android Malware  - Jimmy Shah
    • Attackers are starting to move on from simple attacks, mainly because users are beginning to figure out that the free adult entertainment or chat app shouldn't be sending SMS messages to expensive numbers.  They're leveraging techniques from PC malware like server-side polymorphism, vulnerability exploits, botnets and network updates, and preemptive/direct attacks against security software.  It's not all that bad.  Attackers aren't going out of their way to discover their own vulnerabilities or writing their own exploits.  They're happy to re-purpose the work done by legitimate developers, security researchers, and the rooting community.  If the malware has gotten trickier, what are those tricks?  A look at portions of code and how earlier research is adapted by attackers.

  76. (2012)  Recent Advances in Single Packet Authorization  - Michael Rash
    • Single Packet Authorization (SPA) is a security technology whereby vulnerable services are protected behind a default-drop packet filter and temporary client access is granted via passive means.  This talk will present recent advances in the open-source "fwknop" SPA project, including clients for Android and the iPhone, support for the PF firewall on OpenBSD, the ability to seamlessly integrate SPA into cloud computing environments with the new FORCE_NAT mode, and deploying fwknop on embedded systems with limited computing resources.  In addition, some discussion will be devoted to other SPA implementations and the various tradeoffs that must be made by any project that provides either port knocking or SPA functionality.
    • AI Transcript

  77. (2012)  Re-wired: Hacking the Auditory Experience  - Amelia Marzec
    • Re-wired is a wearable device that translates ambient sound into haptic feedback using bone conduction technology.  Amelia began the project when she lost hearing in one ear.  She was inspired by her new experience of sound that combined tympanic hearing and vibrational resonance.  Amelia began experimenting with less invasive methods for augmenting hearing, using vibration instead of surgery and implants.  Re-wired considers the possibility of empowering patients to place their care into their own hands by building simple devices to take care of simple problems.  This will be a participatory talk on DIY medical technology, including our comfort level with augmenting our own bodies.
    • Re-Wired  Re-wired is is a wearable device that translates ambient sound into haptic feedback using bone conduction technology.
    • AI Transcript

  78. (2012)  SCADA/PLC Exploitation and Disclosure  - Tiffany Rad, Teague Newman, Mike Murray
    • Last year, a few groups of independent security researchers disclosed significant vulnerabilities in SCADA systems and PLCs.  This panel brings together these security researchers to discuss their findings, initial goals for doing the research, disclosure processes, and difficulties and surprises encountered.  These researchers, independently and without corporate or "nation state" funding, decimated the popular belief that "security via obscurity" works to protect critical infrastructure.
    • AI Transcript

  79. (2012)  Sierra Zulu  Or How to Create a Feature Film About the Digital Age - and Why That's Pretty Hard  - Johannes Grenzfurthner
    • Movies are exciting.  Things crash and burn.  Bolts and fists fly.  There are bangs and kabooms.  People go to the cinemas in order to experience new worlds.  But cinema is about to lose its prime source of narrative, having so far tethered to physical action that can be filmed.  Cinema needs tempo.  It needs speed.  The "movement-image" (Gilles Deleuze) depends on physical action onto which the cameras can point.  Yet, in contrast, the real world of non-cinema is losing physical action day by day.  It is a time of abstract, optically unpresentable processes in networks and data systems.  This regress of visual displayability is rather daft.  Cinema has lived well on it for more than a hundred years.  It's easy to create a feature film about a bank robbery, but that's anachronistic.  Some of the most important crimes exist as electronic money movements between international stock exchanges.  Hollywood cinema, on the other hand, still hasn't evolved beyond anything better than banal sequences straight out of an Errol Flynn movie.  How can we accurately portray the stories of our (new) world?  All those dramas and comedies?  All those crimes and stories?  The people at monochrom are working on a feature film called Sierra Zulu.  This talk will discuss their challenges and hopes - and why they think you can help.
    • AI Transcript

  80. (2012)  The Smartphone Penetration Testing Framework  - Georgia Weidman
    • As smartphones enter the workplace, sharing the network and accessing sensitive data, it is crucial to be able to assess the security posture of these devices in much the same way we perform penetration tests on workstations and servers.  However, smartphones have unique attack vectors that are not currently covered by available industry tools.  The smartphone penetration testing framework, the result of a DARPA Cyber Fast Track project, aims to provide an open-source toolkit that addresses the many facets of assessing the security posture of these devices.  This talk will look at the functionality of the framework including information gathering, exploitation, social engineering, and post exploitation through both a traditional IP network and through the mobile modem, showing how this framework can be leveraged by security teams and penetration testers to gain an understanding of the security posture of the smartphones in an organization.  You will also learn how to use the framework through a command line console, a graphical user interface, and a smartphone-based app.  Demonstrations of the framework assessing multiple smartphone platforms will be shown.
    • AI Transcript

  81. (2012)  Social Engineering  - Evil Corley and Friends
    • Since the very first HOPE conference in 1994, the social engineering panel has been a huge draw.  We basically round up a bunch of people who like to play on the phone, tell some stories, and make live calls to strangers who wind up telling us things they really shouldn't in front of a huge crowd of people who are trying very hard not to make any noise.  It's all a lesson on how insecure information really is, and how you can avoid making the same mistakes that some unsuspecting person someplace will inevitably make when this panel randomly calls them.
    • AI Transcript

  82. (2012)  Solving More Than #firstworldproblems  - Johnny Diggz, Willow Brugh
    • For the past two years, Geeks Without Bounds has been using technology to assist people in times of crisis and helping to build better tools to empower people to help themselves.  Whether organizing Random Hacks of Kindness events, teaching app developers about data security, or helping humanitarian organizations engage with hacker communities, they've been bridging the chasm between technology and aid organizations.  Johnny and Willow will present some real world challenges that have bubbled up to the surface and show how you can help us all solve more than #firstworldproblems.
    • AI Transcript

  83. (2012)  Spy Improv: Reality Unfiltered  - Robert Steele
    • Several HOPEs ago, Robert Steele started doing separate Q&A sessions using his knowledge as a former spy, pioneer of open-source intelligence, advocate of multinational sense-making, and #1 Amazon reviewer for nonfiction.  At The Next HOPE (2010), with help from those who stayed with him, he set what may be the world record for Q&A, eight hours and one minute, from midnight Saturday to 0801 Sunday.  This year will be strictly limited to two hours in open session, but the possibility of a roundtable thereafter will remain open.  All questions welcome.
    • AI Transcript

  84. (2012)  The State of HTTPS  - Adam Langley
    • Over the past couple of years, a flurry of developments and events have been happening in the world of HTTPS: from BEAST to HSTS to public-key pinning and mixed scripting.  Some of these are of abstract interest to technical users, and some require action on the part of webmasters.  This talk will cover the broad brush strokes of these developments with a focus on how webmasters can take advantage of them and how to avoid silly configuration mistakes.  In the latter part of the talk, a few expected future developments will be covered.
    • AI Transcript

  85. (2012)  The State of Open-Source Hardware  - Dustyn Roberts, Catarina Mota
    • In the last few years, open-source hardware went from an obscure hobby to a burgeoning movement built on values and practices derived from open-source software, hacker culture, and craft traditions.  This increase is visible in the exponential growth of the community of developers and users, the increase in the number and revenue of open-source hardware businesses, and the emergence of a large number of new DIY gadgets and machinery - from 3D printers and microcontrollers to soft circuits and tech crafts.  The accessibility of hardware plans, along with the communities and collaborative practices that surround them, is lowering the barrier to entry and encouraging people of all ages and walks of life to create, hack, and re-purpose hardware.  Taken together, hackerspaces, the increasing accessibility of digital fabricators, and these open and collaborative practices are leading to an explosion of creativity and innovation reminiscent of the golden years of the Homebrew Computer Club.  This panel will go over the defining events of the last few years to draw a snapshot of the current state of the open-source hardware movement and the impact it's having in hacker culture and beyond.  Also included in the discussion will be the Open Hardware Summit: the world's first comprehensive conference on open hardware, and how it will serve as a venue to discuss and draw attention to the rapidly growing open-source hardware movement.
    • AI Transcript

  86. (2012)  Taking a Bite Out of Logs with Sagan  - Da Beave (Champ Clark III)
    • In protecting today's network infrastructures, organizations have a lot of shiny tools at their disposal.  Firewalls, intrusion detection/prevention systems, network-based ACLs, two factor authentication, and much more.  While these are great tools for detection and prevention of network intrusions, system and network logs are often overlooked.  This talk will discuss using a fairly new open-source (GNU/GPLv2) utility known as Sagan for real-time log analysis.
    • AI Transcript

  87. (2012)  Technology to Change Society: What Not to Do  - Chris Anderson, Gus Andrews, Matt Curinga, Christina Dunbar-Hester
    • Many of us in the hacker/maker communities have a powerful desire to change society by sharing the technologies we're passionate about with those around us.  We're convinced that our way of thinking can lead people to liberation, empowerment, and better lives.  But it doesn't always work the way we hope.  While some technologies support change in certain situations - Twitter and mobile devices in the Middle East and Africa, the printing press and democracy - history is littered with failed technology-driven plans to change the world.  This is where programmers can take a page from social research and history.  There is not, in fact, consensus in the research that "technology teaches itself" or "code is law."  Society is a complex system (people are complex systems!) and overly simplistic beliefs that technology has one universal kind of impact on its users can doom well-intentioned efforts to help others use technology.  What do we need to know about society and how technology changes it in order to be successful?
    • In this panel, Gus will share some basic rules from research on education, political movements, and social change which everyone who wants to write code to change the world should know.  Christina will share cases of activist technical interventions that illustrate the complexity of success or failure, and how inseparable social and technical elements can be.  Chris will do a postmortem of some past projects to change journalism with technology, including the Independent Media Center, discussing their successes and failures.  And Matt will talk about his work to develop a degree in open technology and education at Adelphi University: what he's doing to convince administrators that FOSS technology is important enough to merit its own program, what challenges he faces in talking to educators, and the things in his plan of study which he thinks are most important for politically conscious tech developers to know.
    • AI Transcript

  88. (2012)  Testing the Two Party Tyranny and Open-Source Everything: The Battle for the Soul of the Republic  - Robert Steele
    • Robert was the opening speaker at the first Hackers On Planet Earth conference in 1994 and he's been back every time since then.  In this talk, he will speak about his six week formal campaign as a Reform Party candidate for the presidency in 2012.  He communicated with every presidential candidate less Romney and Obama, and will outline what he learned about "the system," the personalities running for President, and several specific recommendations he has made to the Occupy movement and others about how to reboot the Republic.  His campaign website remains live at bigbatusa.org.
    • AI Transcript

  89. (2012)  Twitter Revolution Meets Surveillance State: Now What?  - The Prophet
    • In the past decade, authoritarian governments have witnessed political upheaval ranging from the Orange Revolution to the Arab Spring movements.  Many governments around the world have responded by more closely monitoring and even censoring telephone, Internet, and mobile communications.  Join TProphet for a detailed and technical look at this censorship and surveillance, how it's being implemented in various countries, the present and future risk to your communications freedom, and what you can do to protect yourself.
    • AI Transcript

  90. (2012)  Using a Space Camp Model for Next Generation Security Training  - Marc Weber Tobias, Tommie R. Blackwell, Matt Fiddler
    • Marc Tobias says the U.S. intelligence community lacks imagination because it doesn't have any kids.  Would an immersive, space camp-type environment ignite kids' interest and be the best way to train them in the art and science of physical, cyber, and electronic security?  Marc and his colleagues need your input on a training model where the world's foremost physical security professionals and cyber-wizards would teach via sophisticated gaming, high-tech tools, cyber-type Hogan's Alley, advanced techniques, and simulators.  The panelists will engage the HOPE audience in an interactive discussion about how to improve America's low "security intelligence" by training young people more effectively.
    • AI Transcript

  91. (2012)  Using Browser-based Tools to Open Up the Web  - Ben Combee
    • In this talk, Ben will show how to use tools already included in the popular web browsers Firefox and Chrome to learn what's really happening when you browse the web.  He'll show how to find hidden values in forms, watch AJAX transactions, and manipulate the data you send out into the cloud, as well as touch on extensions like AdBlock and Greasemonkey and see how they can automate much of this for you.
    • AI Transcript

  92. (2012)  The Weather is Not Boring!  Forecasting, Following, and Photographing Storms  - John Huntington
    • In recent years, real-time weather data and numerical forecast model information has moved from proprietary systems and closed distribution methods to the Internet, and huge amounts of taxpayer-funded weather data in easy to understand formats is now free for all to use.  This has made it easier than ever for anyone to get a good forecast anytime and anywhere, while also allowing storm chasers to leverage their meteorologic knowledge and use mobile Internet technologies and GPS location tracking to chase tornadoes, hurricanes, lightning, and other severe weather.  The presentation will give an overview of weather data gathering methodologies, from ground stations and radar to satellites and weather balloons; give an overview of free or cheap web resources and forecasting models; explain the difference between a "watch" and a "warning;" and show some results from both urban and rural storm chasing.
    • AI Transcript

  93. (2012)  We Will Be Legion: Decentralizing the Web  - Deb Nicholson
    • The popularity of massive centralized services presents challenges for collective privacy, a full diversity of viewpoints, and customized online identities.  Decentralized or federated services are gaining popularity as the answer for users concerned about the one-size-fits-all web.  There is significant work to be done on both the technical and social aspects of federation.  Deb will discuss current alternatives, near to ready projects, and the ones we might want to start thinking about building.
    • AI Transcript

  94. (2012)  When the Founder is Gone: Longevity for Open Projects  - Greg Newby
    • A single visionary is often credited with shaping innovation and leading to success in open-source and open-content projects.  This success doesn't come from that person alone: he or she leads a corps of willing volunteers, admirers, workers, and others who will turn vision into reality - often with some sort of organizational structure, and across a span of years.  This presentation will focus on how to maintain the health and sustainability of such organizations with strong well-known leaders in the event the founder is lost.  The presenter will draw upon personal experience with the recent loss of Michael Hart, founder of Project Gutenberg and inventor of eBooks.  Every organization is different, and every leader is different.  Yet, there are many common characteristics in efforts that started with a single visionary, who led formation of what became a large and successful organization.  The presentation will point out some of these similarities and identify some of the promising strategies that have been effective for continuity.
    • AI Transcript

  95. (2012)  Why Browser Cryptography is Bad and How We Can Make It Great  - Nadim Kobeissi
    • Web apps are becoming almost exponentially responsible for handling user data.  This incredible increase summons an urgent requirement for client-side web browser crypto standards.  However, web browsers lack client-side crypto standards for building blocks such as secure block ciphers, public-key schemes, and hashing algorithms.  Developers currently rely on JavaScript crypto libraries in order to implement these functions, which can, admittedly, provide strong crypto in some situations, but still falter when faced with certain attacks.  This talk will look at Cryptocat, a security-centric web-chat client with client-side cryptography, and also focus on the problems, the solutions, and the limitations of JavaScript cryptography.  There will be a discussion of potential solutions to these problems, which may very well require the implementation of an integrated universal web browser standard for client-side cryptography.
    • AI Transcript

  96. (2012)  Why Names Matter: How Online Identity is Defining the Future of the Internet  - Aestetix
    • As the Internet becomes more public and universal, the world is beginning to have an identity crisis.  Some big questions are coming up: who are we, and how should we be represented online?  Originally inspired by having his Google Plus account suspended twice during the nymwars fiasco, aestetix will explore the deeper nature of how we identify ourselves and each other.  The talk will look at issues both from a technology and social perspective, asking questions like why hacker handles are important, and how our notions of privacy have changed in the greater scheme.  It will also cover the ways in which current online social networks try to build upon existing social relationships and discuss suggestions for improvement in the future.
    • AI Transcript

  97. (2012)  Why You Shouldn't Write Off Higher Education, Young Grasshopper  - John Linwood Griffin
    • This talk is addressed to that kid in the back who's wearing an Utilikilt and a black t-shirt that says "I Hack Charities," who asks, "Why would I bother going to grad school?  I'm self-taught, college was a waste of my time, and universities only exist to train wage slaves."  John will draw from personal experience to describe how in graduate school you get to do what you love, you get to make larger and more structured contributions to the community, you experience personal growth while surrounded by amazing people, you're part of a meritocracy and a close-knit social circle, and the door is open for interesting opportunities afterward.  Included will be a discussion on how hackers can get in.
    • AI Transcript

  98. (2012)  WikiLeaks, Whistleblowers, and the War on the First Amendment  - Ben Wizner, Catherine Crump, John Reinstein
    • The Director of ACLU's Speech, Privacy, and Technology Project will provide an overview of the Espionage Act and the other statutes that the government has employed to prosecute leakers and threaten publishers.  Ben will discuss the ACLU's litigation on behalf of WikiLeaks supporters whose Twitter records have been subpoenaed and whose laptops have been seized by government agents, and will place the Obama administration's unprecedented campaign against leakers in legal and historical context.
    • AI Transcript

  99. (2012)  Your Cell Phone is Covered in Spiders!  (An Overview of Mobile Device Security)  - Cooper Quintin
    • Smartphones have changed the world.  Your calendar, photographs, private documents, and communication with your entire social sphere is now just a swipe away.  We are carrying exponentially increasing amounts of highly personal data around with us in our pockets.  But are we doing enough to safeguard this data?  Mobile devices are also becoming an important tool for social change, but with this they also become a more important target for governments and corporations.  With so many attack vectors on mobile devices, it is important to know the ways that your mobile device can be compromised and how you can protect against these attacks.  This talk will focus primarily on the security of the Android operating system.  You will hear about how to protect your phone against warrantless search and seizure by law enforcement, as well as how much damage malicious apps can actually do and how to protect yourself from becoming the victim of malware.You will hear about password security concerns on Android and how to protect yourself, along with some of the many great security-related apps that Android has to offer.  This talk will examine the question of whether you can protect yourself from the greatest of all threats to your phone: The Phone Company.
    • OSTel
    • AI Transcript

  100. (2012)  Closing Ceremonies  -
    • Don't even think of leaving early on Sunday.  This is where you get to celebrate the end of another HOPE conference and start looking forward to and planning the next one.  (Maybe we'll even tell you what the next one will be called if you stick around.)  You'll also hear a lot of the story behind what it took to put this event together.  Oh yes, and did we mention that we give away prizes during this final gathering?  Well, we do, and they're awesome.  You now have all of the reasons you need to stay into the evening on Sunday and get the most out of HOPE.  Monday will wait.
    • AI Transcript



HOPE X





  1. (2014)  A Conversation with Edward Snowden  - Daniel Ellsberg, Edward Snowden, Trevor Timm
    • We had to keep this bombshell quiet til the last minute since some of the most powerful people in the world would prefer that it never take place.  (Even at this stage, we wouldn't be surprised at mysterious service outages, but we believe the hacker spirit will trump the unprecedented might of the world's surveillance powers.  Fingers crossed.)
    • Daniel Ellsberg has been an inspiration to Edward Snowden and Ellsberg himself has expressed his admiration of Snowden's actions in releasing information revealing the extent of NSA's spying on civilians around the globe, including within the United States.  Ellsberg changed the conversation in the height of the Vietnam War through the Pentagon Papers - by revealing deceptive practices by the government.  Snowden has also dramatically changed the conversation on surveillance and intelligence-gathering with his revelations.  We're honored and proud to have HOPE be the forum via which these two American heroes converse.  Snowden is, of course, still unable to leave Russia because of the threat he faces from the authorities in the United States.  So he will be joining us and speaking on a video link right after Daniel Ellsberg's keynote.

  2. (2014)  Keynote Address: Daniel Ellsberg  - Daniel Ellsberg
    • We're thrilled that the whistleblower of all whistleblowers - Daniel Ellsberg - will be one of our keynote speakers this year.  Ellsberg was the cause of one of the biggest political controversies ever seen in the United States when he released the Pentagon Papers in 1971 and changed history.  We are honored that Daniel Ellsberg recognizes the value and importance of the HOPE X conference and it's great to know that he'll be able to speak in person to a whole new generation of individuals who will also shape the direction of the world one day.  We can only hope they'll also be ready to stand up for their convictions, no matter the cost.

  3. (2014)  The Hacker Wars - A Conversation with NSA Whistleblower Thomas Drake  - Thomas Drake, Vivien Lesnik Weisman
    • Vivien Lesnik Weisman, director of the upcoming documentary film The Hacker Wars, speaks with Drake on the confluence of hacktivism and whistleblowing.  Depending on one's perspective on who should regulate information, hacktivists and whistleblowers are either criminals or freedom fighters.  Drake will discuss his own case and the dystopian dynamic that ensued when the criminal justice system was used as an instrument to destroy him.  In light of his personal experience with the state, he will discuss the importance of specific stories of young hacktivists, along with that of whistleblower Edward Snowden, including their battles with the U.S. government.
    • The Hacker Wars

  4. (2014)  #radBIOS: Yelling a Database Across the Room  - Richo Healey
    • How can you distribute digital information using only sounds and computers?  Frustrated by the lack of compatibility of wireless hardware in the wild, it was concluded that the audible spectrum was the "One True Way" to distribute knowledge.  This talk will introduce Groundstation, an append-only graph database, and detail the journey of integrating it with the unambiguous encapsulation research of Ossmann/Spill to achieve its ultimate goal - the audible sharing of digital knowledge.
    • AI Transcript

  5. (2014)  (Geo)location, Location, Location: Technology and Countermeasures for Mobile Location Surveillance  - Matt Blaze
    • We all know that law enforcement (and private companies, for that matter) can track you through your mobile phone.  But how exactly does tracking work?  How precise are they?  When can they get this data?  And is there anything you can do to obscure your movements without moving into a Faraday cage?  This talk will discuss the various technologies that law enforcement, intelligence agencies, and private industry use to track individual movements.  There are a surprising number of different techniques.  Many involve the signals emanating from - and records created by - mobile phones, but there are more specialized - and surprising - tracking techniques in use as well.  The tower data information contained in cellular call detail records, E911 "pings," tower dumps, IMSI catchers, aggregate metadata analysis, Wi-Fi and Bluetooth-based locators, traditional RF and GPS trackers, and some of the sophisticated "implants" used by intelligence agencies will all be discussed.  Can you opt out without opting out of the Information Age?  Not always, but there are a few countermeasures that work, as well as a surprising number that don't.  There will be an analysis of a number of real-world cases of tracking, as well as tips on how to learn from the mistakes of others.
    • RAYMONDLINN - Rayhunter Project

  6. (2014)  A Beautiful Mosaic: How to Use FOIA to Fight Secrecy, Explore History, and Strengthen American Democracy  - Michael Morisy, Michael Ravnitzky
    • The Freedom of Information Act (FOIA) is a simple but powerful tool that permits any citizen to find out more about what their government does, permitting more informed participation in American society and government processes.  This presentation will show how public records released under FOIA have been used to expose questionable surveillance programs, domestic drone programs, and even an exploding toilet.  It also highlights the availability of an array of free, public resources to explore millions of pages of government records that have already been released, so you can see the results of your tax dollars at work.  This talk will also review ways of overcoming some common agency roadblocks to get the records and data you want.  Examples will be drawn from the GovernmentAttic.org and MuckRock web sites.  Two comprehensive workshops will follow: Basic FOIA Workshop, and FOIA Advanced Strategies and Tactics.

  7. (2014)  A Sea of Parts  - Per Sjöborg
    • Have you heard of Self-Reconfiguring Modular Robotics (SRCMR)?  This new technology enables robotic modules to configure themselves into whatever you need, whenever you need it, which offers many benefits.  If we could create a common pool that modules can be drawn from when they are needed and returned to when they are not, we could further leverage the benefits of SRCMR.  The challenge is that the pool is not intrinsic to an SRCMR system; we need to create it.  We need a new understanding of our common resources and an acceptance for sharing them.  If we can create the pool or "a sea of parts," it will bring the same benefits to physical systems that shared web hosting has brought to the web.  This will allow quick and cheap development and deployment of new ideas.

  8. (2014)  A Story of Self-Publishing Success  - John Huntington
    • Just days before HOPE Number Nine, John Huntington released a self-published version of his book, Show Networks and Control Systems.  Several months before, his publisher had decided that they were not interested in an update after three successful editions, so Huntington got his publishing rights back and did a whole new edition himself using Amazon's Createspace for printed copies and Kindle for eBooks.  And it's been a success - Huntington has made far more money self publishing this one edition than the royalties on all three of the previous editions with the publisher combined.  More importantly, he has had a far higher level of engagement with his readers, and has been able to do things he never could have done with the publisher, like putting free lecture videos for each chapter on his website, or giving copies away (which he will do at the end of this talk).  Huntington will share sales figures, compare the economics and issues related to both printed and eBook editions, and lay out the challenges, pitfalls, and successes of this process.

  9. (2014)  Apophenia: Hunting for the Ghost in the Machine  - Wil Lindsay
    • This discussion will look at the practice of exposing anomalies in network communications and computer processes in order to find evidence of interference (or intentional communication) from beyond the grave.  Known as Instrumental Trans-Communication (ITC), the practice has roots as far back as the 1930s and has survived into the digital era.  We will look at how these same methods are now being applied to Wi-Fi networks, custom software development, remotely networked sensors, and digital spectrogram systems designed to capture images of the spirits of the deceased.  (The discussion will be accompanied by a basic circuit workshop where participants can build a simple device with accompanied software to collect data and test the methods discussed in the presentation.)

  10. (2014)  Are You Ready to SIP the Kool-Aid?  - Richard Cheshire, Gaston Draque
    • Session Initiation Protocol (SIP) is the gateway drug to VoIP (Voice over Internet Protocol).  You will see how such a phone call is set up, and will witness an in-depth discussion of Asterisk, the open-source PBX software that represents the new age of telephone switching in the 21st century.

  11. (2014)  Art Under Mass Surveillance  - !Mediengruppe Bitnik
    • !Mediengruppe Bitnik are contemporary artists.  In their talk, they will show two examples of their work, illustrating the translation of hacking from the computer field into an artistic practice.  Bitnik will show how to hack the opera in ten easy steps and what happens when you send a parcel with a hidden live webcam to Julian Assange at the Ecuadorian Embassy in London.

  12. (2014)  Ask the EFF - This Year on the Internet  - Nate Cardozo, Kurt Opsahl, Adi Kamdar, Peter Eckersley, Eva Galperin
    • Hear from lawyers, activists, technologists, and international policy analysts from the Electronic Frontier Foundation, the nation's premiere digital civil liberties group fighting for freedom and privacy in the computer age.  Since HOPE Number Nine, much has happened on the Internet.  From Aaron Swartz' tragic death to Edward Snowden's revelations, from TPP to Stop Watching Us, they will put it all in context and answer your questions.  This session will include updates on current EFF issues such as their efforts to end mass spying both at home and abroad, their fight against the use of intellectual property claims to shut down free speech and halt innovation, a discussion of their technology projects to protect privacy and speech online, updates on their cases against the NSA, litigation and legislation affecting security research, what EFF is doing to open access to scholarly works, how they're fighting the expansion of the surveillance state, and much more.  Half the session will be given over to Q&A, so it's your chance to ask EFF questions about the law and technology issues that are important to you.

  13. (2014)  Barrett Brown and Anonymous: Persecution of Information Activists  - Kevin Gallagher, Ahmed Ghappour, Gabriella Coleman
    • Barrett Brown, a Dallas-based writer and freelance journalist, was arrested in late 2012 and indicted several times on charges including the publication of a hyperlink.  He was earlier pegged by the media as an "unofficial spokesperson" for the hacktivist collective known as Anonymous.  But who is he really and what was he trying to uncover that made him a target of the feds?  The prosecution was widely regarded as excessive and included a gag order, subpoenas, charges issued against family members, attempts to seize defense funds, and criminal counts so flawed that they were later dismissed.  This talk will explore Brown's work, what happened during his case, the dynamics of his interactions with Anonymous and its implications for other journalists who work with hackers, and why his case outraged many of those who care for free speech and freedom of press.

  14. (2014)  Biohacking and DIYbiology North of the 45th Parallel  - Kevin Chen, Connor Dickie
    • In the past few years, there have been foundational developments enabling hobbyists and seasoned professionals to research and develop the life sciences outside of classical institutions.  Known as DIYbiology or biohacking, this shift in the bio-world takes its inspiration from mature hacker and open-source cultures.  In this panel, Canadian biohacker successes and struggles will be presented.  Current legal, economic, and political landscapes that affect Canadian and global biohackers will be discussed and compared.  What constraints and challenges are faced when it comes to doing synthetic or molecular biology outside of its conventional confines?  How is the community membership growing and what does it take to accelerate this growth?  Lastly, what growth are we anticipating for independent and open biotech research, as well as inter-laboratory and international collaboration?  And how can the audience and other hacker communities get involved in this exciting shift?

  15. (2014)  Bless the Cops and Keep Them Far from Us: Researching, Exploring, and Publishing Findings While Staying out of Legal Trouble  - Alexander Muentz
    • We all like to tinker and explore.  Hacking, exploring, and publishing findings is important to our community as well as the world at large.  Unfortunately, law enforcement and the operators of the systems you investigate may disagree and use the legal system to threaten or silence you.  How can hackers, pen-testers, and security researchers all protect themselves?  Can you reverse engineer a device you just purchased?  Can you investigate a security hole in another's web server?  What can you tell others about your findings?  This talk will consider how current U.S. laws affect one's ability to explore systems, collaborate, and publish findings.  Q&A will follow.

  16. (2014)  Blinding the Surveillance State  - Christopher Soghoian
    • We live in a surveillance state.  Law enforcement and intelligence agencies have access to a huge amount of data about us, enabling them to learn intimate, private details about our lives.  In part, the ease with which they can obtain such information reflects the fact that our laws have failed to keep up with advances in technology.  However, privacy enhancing technologies can offer real protections even when the law does not.  That intelligence agencies like the NSA are able to collect records about every telephone call made in the United States or engage in the bulk surveillance of Internet communications is only possible because so much of our data is transmitted in the clear.  The privacy enhancing technologies required to make bulk surveillance impossible and targeted surveillance more difficult already exist.  We just need to start using them.
    • AI Transcript

  17. (2014)  Bootkits: Step-by-Step  - Eric Koeppen
    • Basic Input/Output System (BIOS) is firmware that boots older machines.  Unified Extensible Firmware Interface (UEFI) is a combination of firmware and a boot-loader that boots newer machines.  As a result of the leaks by Edward Snowden, the possible existence of rootkits that can affect the BIOS and UEFI has been widely reported.  Both of these technologies exist in memory that is not typically accessible remotely, which makes infection particularly difficult.  The location of these technologies is even difficult to reach by the operating system, which makes detection of such an infection at this level also a difficult problem.  This talk will explore all of the steps that need to take place in order to accomplish this feat, review creative measures malware has taken to tackle these problems, and review methods for detection of these kinds of infections.

  18. (2014)  Bringing Down the Biological System: How Poisons Hack the Body  - Jennifer Ortiz
    • Poisons can kill... but how?  Why are some chemicals beneficial in small quantities but lethal in large amounts?  How does a sometimes miniscule amount of chemical bring the whole system down?  And how can these processes be counteracted such that the system may survive?  Learn about how the complex cellular network of our body works and what happens when this network is disrupted.

  19. (2014)  Building an Open-Source Cellular Network at Burning Man  - Johnny Diggz, Willow Brugh
    • There is literally nowhere else on earth where you can run an experimental mobile phone network with a potential 50,000 users and get away with it (legally).  Nowhere else can you learn so much in as short a timeframe about people's relationships with their mobile phones or what makes a mobile network tick.  Since 2006, the folks behind OpenBTS have been running the Papa Legba camp at Burning Man, providing fully licensed independent (free) GSM cellular service in the most unlikely of places.  Johnny and Willow will go through the hardware and software tools they deployed in 2013, along with a discussion of lessons learned and future plans.

  20. (2014)  Can You Patent Software?  - Ed Ryan
    • Patent law is a subject of general loathing among hackers and those in the open-source movement.  While a few grudgingly agree that some things might be worthy of patents, the idea of patenting software seems to offend core values of our community.  Despite that fury, it is difficult to pin down exactly what a software patent is.  To what degree is a patent directed to software instead of a new and useful machine?  How can you separate out those two concepts?  This talk aims to present the core problems of software patents in a way that is accessible to hackers and other technologists and, in particular, will address the Alice Corp. decision by the Supreme Court in June.  This talk is an academic discussion of patent law and should not be construed as legal advice.

  21. (2014)  Codesigning Countersurveillance  - Sasha Costanza-Chock, Emi Kane
    • Recent revelations about massive data collection by the National Security Administration have brought sustained popular attention to the rise of pervasive surveillance systems.  We have entered a moment of important dialogue about the surveillance state, the role and ethics of technology companies, the potential harms of mass surveillance to civil liberties and human rights, and the need for interventions involving technology, policy, and social practice.  At the same time, the voices of communities that have long been most explicitly targeted by surveillance have been largely excluded from the debate.  There are multiple, overlapping surveillance regimes, and they disproportionately target people of color, low-income, and working people, as well as activists in general.  State, military, and corporate surveillance regimes are growing in scope, power, and impunity, not only in countries such as Iran, Syria, and China, but also within liberal democracies such as the United States, India, and Brazil.  This talk will focus on projects and process from the MIT Civic Media Codesign Studio, which works with community-based organizations to develop civic media projects that connect to grounded strategies for social transformation.

  22. (2014)  Community Infrastructure for FOSS Projects  - James Vasile
    • At HOPE Number Nine in 2012, James spoke to people about how to build community infrastructure to provide support at a scale larger than just one project at a time.  Then he went and built some.  This talk is about lessons learned - how to replicate the successes and avoid the failures he's experienced in the last two years.  The focus will be on his two case studies: 1) the formation of a localization community for anti-censorship and anti-surveillance tech (which went reasonably well) and 2) creating a heavier-weight code auditing organization for anti-censorship and anti-surveillance tech (which had some hiccups).  There are lessons in both and they will be the basis of discussion here.  The goal is to also seed some ideas on how to build this kind of infrastructure for other niches and the wider free software community.

  23. (2014)  Community Owned and Operated Cellular Networks in Rural Mexico  - Peter Bloom, Maka Muñoz
    • Why try to avoid them spying on us on their networks when we could just build our own?  This is what the Rhizomatica project has done in rural Mexico, where they help to build and maintain community owned and operated GSM/cellular infrastructure.  Come and hear about experiences in the field and how to deal with the technological, legal, social, and organizational aspects that come along with operating critical communications infrastructure from a community emancipation and autonomy perspective.  If you enjoy freedom, community, and dismantling the corporations and governments that seek to monitor, control, and exploit us, then this presentation is for you.  The talk will not be overly tech-focused, so don't worry if you haven't got the faintest idea or couldn't care less how a cell phone network operates.  If you want tech and geekiness, you can also attend the workshop: "How to Build and Run Your Own Cellular Network."
    • AI Transcript

  24. (2014)  Crypto for Makers: Projects for the BeagleBone, Pi, and AVRs  - Josh Datko
    • As more devices join the Internet of Things, it is increasingly important that these devices remain protected from surveillance and compromise.  This talk will show how to add specialized, commercially available, crypto Integrated Circuits (ICs) to improve the security of your BeagleBone, Pi, or AVR based platform.  ICs such as a Trusted Platform Module, I2C authentication chips, and hardware random number generators will be discussed.  The CryptoCape, an Open-Source Hardware daughterboard, made in collaboration between SparkFun Electronics and the presenter, will be presented in detail.  Lastly, this talk will describe the experience of running a Tor relay on a BeagleBone Black for over 200 days.

  25. (2014)  Cultures of Open-Source: A Cross-Cultural Analysis  - Sandra Ordonez, Bryan Nunez, Douwe Schmidt
    • While a common philosophical and cultural thread ties all of us in open-source together, the ecosystem is as diverse as the world itself.  In fact, open-source projects are a kaleidoscope of cultures that influence how they are approached, how teams interact, outcomes, and what type of people they attract.  At the same time, open-source is suffering greatly from a lack of diversity.  Three percent are women, and many users from non-English subgroups feel their voices are not heard in the OS ecosystem.  This panel will discuss: how open-source projects can build bridges to help incorporate people from non native English speaking communities, examples of when lack of cross-cultural sensitivity goes wrong, descriptions of patterns and regional differences observed in various open-source communities, and why the Dutch are some of the best open-source volunteers ever.

  26. (2014)  Cyber Security in Humanitarian Projects as a Social Justice Issue  - Lisha Sterling
    • Without secure code and implementation, humanitarian projects can be used against the very people they are designed to help.  This is a basic problem of social justice.  If security is only available to people with money, privilege, and the fortune to not be in the midst of a disaster, then there is no security.  As Internet crime rises and security solutions gain momentum, vulnerable populations are left out of the protection that the privileged few enjoy.  Issues of trust, budgetary restrictions limiting low-barrier digital security tools, and the mass surveillance/digital disenfranchisement of the non-elite are the obstacles to a secure commons.  Community building and resource sharing on the Internet is only accomplished when we take part in building social justice by using our skills to improve open-source code security and its implementation across the humanitarian ecosystem.

  27. (2014)  Dark Mail  - Ladar Levison, Stephen Watt
    • The Dark Mail Initiative represents a collaborative effort to bring about a new generation of standards designed to provide automatic end-to-end encryption for email.  The presentation will cover the "dmail" architecture, with a focus on the key elements of the design that allow it to overcome some of the most problematic traditional usability issues, all the while preserving a world-class guarantee of security.  Dark Mail stands in a unique position against most competing technologies because of its commitment to complete transparency, both in the proposed open dmail specifications and in the open-source implementation that is targeted for release later this year.  The talk will also include a short discussion of the Lavabit legal saga that precipitated the dmail development effort, the design goals of the project, and an explanation of why these goals are important, both to the computer security community and to society at large.  The discussion will conclude with a short update on the status of the reference implementation development effort.

  28. (2014)  Disruptive Wearable Technology  - Becky Stern
    • As technology becomes ever more embedded in the fabric of our society and even our clothes, we must grapple with ever more complicated tradeoffs regarding privacy and security.  This talk will highlight disruptive wearable technologies that creatively and assertively address these modern technological and societal changes.  Come learn about underwear that that tattles on a TSA agent's wandering fingers during a secondary screening, makeup that makes you imperceptible to facial recognition software, and eye-tracking glasses that let a paralyzed graffiti writer tag again.  Most projects featured are open-source or how-to guides, and span the last ten years.  Becky Stern's intention is to inspire HOPE X attendees to think more about the physical body as a canvas for hacking, social engineering, fashion, and wearable tech.

  29. (2014)  DIY Usability Research: A Crash Course in Guerrilla Data Gathering  - Kaytee Nesmith
    • Good news: it's becoming abundantly clear that more and more people want to use surveillance circumvention tools to protect their privacy.  Bad news: most people can't figure out how to use them.  Thankfully, usability research is no longer difficult to arrange or afford.  Anyone - developers, designers, and project managers alike - can conduct user testing at any time, in any setting.  In this presentation, you will learn everything you need to know to get started on your own qualitative user research, how it can help you understand and solve for your users' needs, and what it means for the future of surveillance circumvention technology.

  30. (2014)  Drop It Like It's Hot: Secure Sharing and Radical OpSec for Investigative Journalists  - Harlo Holmes, Aurelia Moser, Barton Gellman
    • As developer-journalists, Harlo and Aurelia work with sensitive information about critical investigations of governments, institutions, and individuals - domestic and foreign.  (((Barton Gellman))) of the Washington Post is one of three journalists who received classified NSA archives from Edward Snowden.  The security and reliability of the information these panelists handle is of the utmost importance.  Managing their resources and notes while maintaining the privacy and safety of their sources can be complicated as they work on collaborative teams of varying technical and subject expertise.  This talk will go over how journalists collaborate covertly in the newsroom, reviewing some tools and applications for dead-dropping data, and protecting privacy where possible, at places like the Washington Post, the Guardian Project, The New York Times, Ushahidi, and Internews Kenya.

  31. (2014)  Echoes of Returns Lost: The History of TELECOM Digest  - Bill Horne
    • This talk is a brief history of the people and events which shaped TELECOM Digest's history, presented by its current editor.  (TELECOM Digest is the oldest continuously running electronic magazine about telecommunications on the Internet - and one of the oldest mailing lists still on the Internet in any category.)  Bill will discuss the previous moderators and the events that led to his stewardship.  There will be anecdotes from the archives, some discussion of the personalities that formed the digest, and brief speculation about its future.  There have been some truly memorable posts over the years which will be focused upon.  The day-to-day workflow will be described, along with the ways things have changed over the years, from manual efforts to Usenet access to the current Majordomo II list management software.  Hear about the evolution of the digest from a mostly "Bell" centered e-zine, to the Wild West days of MCI and Sprint, up to the re-consolidations now underway.  In addition, Bill will explain his philosophy of moderation and the ways he goes about it while seeking to lighten the moderator's technical workload, automate manual procedures, and his preparations to adapt for the new YaGooMail "walled garden" paradigm.

  32. (2014)  Electric Waste Orchestra: Learning and Teaching Music, Electronics, Programming, and Repurposing  - Colten Jackson
    • The technology to turn e-waste into musical instruments is free, open-source, and waiting to be fully explored.  At this talk, you'll learn how the computer junk piling up in IT departments everywhere can be transformed into novel input devices, allowing kids and adults alike to create physical instruments to control electronic music.

  33. (2014)  Elevator Hacking: From the Pit to the Penthouse  - Deviant Ollam, Howard Payne
    • Throughout the history of hacker culture, elevators have played a key role.  From the mystique of students at MIT taking late-night rides upon car tops (don't do that, please!) to the work of modern pen-testers who use elevators to bypass building security systems (it's easier than you think!), these devices are often misunderstood and their full range of features and abilities go unexplored.  This talk will be an in-depth explanation of how elevators work... allowing for greater understanding, system optimizing, and the subversion of security in many facilities.  Those who attend will learn why an elevator is virtually no different than a staircase as far as building security is concerned!

  34. (2014)  Ergonomic Human Interface Hacking  - Carl Haken
    • Do you experience numbness or weakness in your hands?  Do you have a permanent case of Emacs pinky?  Are you playing vi golf for your health?  Since the release of the Macintosh 30 years ago, mainstream human-computer interfaces have changed little, and hardcore computer users (hackers, coders, gamers, etc.) are paying the price.  This talk will examine potential solutions to the repetitive strain injuries commonly experienced by computer users, including: head-based cursor control, ultra-ergo keyboards, foot pedals, and other optimizations.

  35. (2014)  Ethical Questions and Best Practices for Service Providers in the Post-Snowden Era  - Nicholas Merrill, Ladar Levison, Declan McCullagh
    • Service providers have always had to shoulder a tremendous ethical burden because of the volume of personal information they hold, including files, metadata, and geolocation data.  Some, like Calyx and Lavabit, have been willing to take extra steps to protect their customers' privacy rights.  After Edward Snowden's revelations about the U.S. government, some larger providers have become more willing to fight for their users in court or speak publicly about surveillance demands.  But many court dockets remain sealed.  This talk will explore the telecommunications privacy landscape as we now know it, including the extent of the surveillance regime that some of us suspected all along.  The focus will be on best practices for service providers at many levels: software design, API design, network design, policy, and more.

  36. (2014)  F*ckhackerf*cks!  An Audience Bashing  - Johannes Grenzfurthner
    • Johannes Grenzfurthner of art tech group Monochrom will indulge in a public rant about hacker culture and why it has to be saved from itself.  Expect strong language, indecency, and valid critique of the status quo of hackdom.  (No wonder his 2008 Google Tech talk got censored and never made it onto Google's YouTube channel.)
    • AI Transcript

  37. (2014)  G-code: The Programming Language of Machining and 3D Printers  - Todd Fernandez
    • This talk will provide an explanation of the G programming language commonly known as "G-code."  G-code was originally developed in the 1950s to allow numerical control of industrial manufacturing equipment.  G-code's major user base is not traditional programmers or software engineers, but machinists, manufacturing programmers, and those who own 3D printers.  In modern times, it is used to control everything from a home-built RepRap to massive CNC milling machines to make anything you could possibly imagine.

  38. (2014)  Hacking Money, from Alexander the Great to Zerocoin  - Finn Brunton
    • Cryptocurrencies are here.  Bitcoin is in the news and in the courts, and many other currencies are following, offering everything from anonymous transactions to redistributive economies to monetary sovereignty to, of course, doges.  Related platforms promise to reinvent DNS, cloud storage, voting, contracts, even the corporation itself.  To really understand what's happening, and how we can steer cryptocurrencies towards accomplishing social and political goals, we need to connect the breaking news with the deeper history of the technology of money.  This will be a look back - before Hashcash and DigiCash, before Chaum, May, Diffie, Hellman and Merkle - and forward, into the future to plausible scenarios and speculations for launching projects now.  What connects Belfast pubs in 1970 with the vault of the New York Federal Reserve, trading networks of the Islamic golden age, an Austrian ski village during a global depression, willows by the Thames, and an extraterritorial fortress on the outskirts of Singapore Changi Airport?  Why are survivalists filling ammo boxes with rolls of U.S. nickels?  Why do the differences in hash algorithms matter, and what covert software agreements underwrite the verification of physical bank notes?  Money is one of the most significant social technologies that humans have invented, and cryptocurrencies are an opportunity to hack on the architecture of trust, verification, value, and credit that shapes how we can live.  This talk, and conversation during and after, will explore what we can do with this opportunity.

  39. (2014)  Hacking the Patent System: The Vulnerabilities That Allow for Bad Patents and How to Stop Them  - Charles Duan
    • We are hearing about the problems of software patents everywhere: in the tech blogs, in the mainstream news, from the President, and even out of the Supreme Court.  We hear stories of patent trolls destroying technology companies and small businesses with patents on such simple ideas as scanning to email or in-app purchases.  How did we end up with a patent system that generates patents that become the tools of legal abuse?  This talk will look at the patent system like an insecure OS, one rife with vulnerabilities in dire need of patching.  Just as an unsecured computer can be misused to the ends of malicious users, vulnerabilities in the patent system allow clever lawyers and patenters to obtain patents on simple ideas, ones that anyone with an ounce of programming skill would find obvious.  We will look at how to get a patent on comparing and adding two numbers - a patent that actually exists right now.  We will consider the flaws in the system that allow aggressive patent holders to exploit weak patents and extract money from real innovators.  And we will talk about how to fix that system - but only with the help of all of us who care about the future of technology.

  40. (2014)  Hearses and Hand-Held Calculators: The Unlikely Connections That Shaped Modern Technology and Tech Culture  - Bill Degnan
    • Explore unlikely connections between well known milestones in technology, tech culture, and seemingly mundane things and events that helped bring them into being.  The importance of these seemingly insignificant sparks could not have been imagined at the time of their introduction.  The discussion starts with the story of how the Casio mini calculator led directly to the formation of the software giant Microsoft.  Next, the talk will explore how early 1970s minicomputer field techs accidentally invented the first personal microcomputers,i predating the Altair, IMSAI, and Apple I.  The conversation will move to the hidden connections between Datapoint computer company CEO Harold O'Kelley, the Intel 4004 processor, and the eventual dominance of the Ethernet networking protocol over token ring and ARCnet.  The presentation will conclude with a story of unlikely connections between a 1963 hearse, the Commodore 64 version of the Ghostbusters! software package, and the true uncredited originator of the story that the film and game was based on.
    • Adventures Into The Unknown comic - Issue #146
    • AI Transcript

  41. (2014)  How to Prevent Security Afterthought Syndrome  - Sarah Zatko
    • Outside of the hacker community, security as an afterthought has always been the norm.  Too often we see the following: systems designed without thought for security, then later that system is compromised, and finally a hastily created patch is released (if we're lucky).  But did you know that this "security as an afterthought" approach is what we currently teach in schools?  Yes, even many of the best schools teach and treat security as a separate topic, leaving it for an advanced class that interested seniors or graduate students might choose to take as an elective.  It is all too easy for an undergraduate student to gain a computer science degree without ever learning about the security concepts relevant to their specialty.  Security is an integral facet of just about every topic in computer science.  Rather than treating security as an afterthought, something that we address after all the foundations are fully in place, it should be treated as an integral part of networking, programming languages, operating systems, and just about every other computer science discipline.  Especially offensive aspects!  Fixing the way we teach security is a tall order, but it's a more lasting solution.  Most short term solutions are Band-Aids on the root problem.  Perhaps most encouragingly, we have an existence proof of security being successfully integrated in other fields.  This talk will cover computer science curricula, how security is taught and integrated throughout course work in academia, and evaluate an exemplar in a different science where security is being integrated in early curriculum.

  42. (2014)  HTTP Must Die  - Yan Zhu, Parker Higgins
    • We all know that HTTP is insecure, but the Snowden revelations of 2013 showed that insecurity runs far, far deeper than most of us could have imagined.  It's bad enough, in fact, that anyone who still supports it is contributing to the weaponization of the Internet by government spy agencies.  The speakers believe that nobody at HOPE X has any excuse to be using plain HTTP instead of HTTPS in 2014.  In this talk, they will summarize what the Snowden revelations mean for protecting data in transit: scary stuff like how supposedly secure cookies on social network sites can be turned into custom beacons for marking victims of targeted malware.  They'll talk about what every web service provider needs to do at the very minimum to mitigate these attacks, and what clients can do to protect themselves.  Finally, they will share some success stories from the last year that show how Edward Snowden has raised the bar for web security and created a safer online landscape for the average user.

  43. (2014)  I Am The Cavalry: Lessons Learned Fuzzing the Chain of Influence  - Geoff Shively, Beau Woods, Jen Ellis, Andrea Matwyshyn
    • I Am The Cavalry is a relatively new grassroots organization with volunteers from around the world, focused on issues where computer security intersects public safety and human life.  Their mission is to ensure that these technologies are worthy of the trust we place in them.  Manufacturers of medical devices, automobiles, home electronics, and public infrastructure have been quickly adopting computing technologies.  Our dependence on computer technology is increasing faster than our ability to safeguard ourselves.  Our technology has advanced to the point where we no longer have to ask "can we?" but we rarely ask "should we?"  The hope is to fix this through education, outreach, and research.  Hear lessons learned from fuzzing the chain of influence, getting root in the C-Suite, escaping echo chamber sandboxing, initiating two-way handshakes, and building human protocol-aware processes, etc.

  44. (2014)  Identifying Back Doors, Attack Points, and Surveillance Mechanisms in iOS Devices  - Jonathan Zdziarski
    • The iOS operating system has long been a subject of interest among the forensics and law enforcement communities.  With a large base of interest among consumers, it has become the target of many hackers and criminals alike, with many celebrity thefts of data raising awareness of personal privacy.  Recent revelations exposed the use (or abuse) of operating system features in the surveillance of targeted individuals by the NSA, of whom some subjects appear to be American citizens.  This talk identifies the most probable techniques that were used, based on the descriptions provided by the media, as well as today's possible techniques that could be exploited in the future, based on what may be back doors, bypass switches, general weaknesses, or surveillance mechanisms intended for enterprise use in current release versions of iOS.  More importantly, several services and mechanisms will be identified that can be abused by a government agency or malicious party to extract intelligence on a subject, including services that may, in fact, be back doors introduced by the manufacturer.  A number of techniques will also be examined in order to harden the operating system against attempted espionage, including counter-forensics techniques.
    • Identifying Back Doors, Attack Points, and Surveillance Mechanisms in iOS Devices  Paper in Digital Investigation

  45. (2014)  Jumping the Carbon-Silicon Boundary for Fun and (Mostly) Profit  - Tom Keenan
    • Kevin Warwick made history in 1998 with an RFID chip implanted under his skin.  He went on to use sophisticated electrodes to control a robotic arm, achieved human to human nervous system hookups, and even tried transatlantic teledildonics with his wife.  Fast forward to 2014 as eager consumers strap on wearable fitness monitors and allow Samsung's creepy eye icon to track their gaze, just so their video will pause when they look away.  Worried about Google learning your habits from your Nest thermostat?  Your Nike+ FuelBand probably knows a lot more about you, like those times you burned 150 calories at 3 am without taking a single step.  Japan's smart toilets realize you're getting sick before you do, and they can tell your doctor.  Or, perhaps, your insurance company.  This talk presents some of the most intriguing privacy-invading body technologies and looks forward warily to the near future, when the skin cells you leave on a store's PIN pad might be DNA sequenced without your knowledge.  You won't believe how many people are after your body-data, and how much it's going to be worth on the open market.  There are things you can do to protect your bio-privacy, but you have to start now!

  46. (2014)  Keeping Old Code Alive: The Venerable LambdaMOO Server in 2014  - Todd Sundsted
    • The LambdaMOO server, the application server that still powers the LambdaMOO online community and that was the engine for hundreds of other text-based virtual worlds (MUDs), was first released over 20 years ago, in 1991.  MUDs (Multi-User Dungeons) were the first networked virtual worlds; and they were popular long before Second Life, World of Warcraft, and MMORPGs in general made their appearance.  Even though much of the code in the current LambdaMOO server is unchanged from the early 1990s, people today still download the code, compile it, and build little worlds with it.  Motivated by a desire to build simple little immersive experiments that users could interact with and extend via programming, but frustrated by LambdaMOO's lack of features as well as source code that was several decades away from modern best practices, Todd spent the last four years modernizing the server, and building applications and a library of application building blocks.  The result is a fork of the codebase called Stunt that speaks HTTP (instead of telnet), includes up- to-date cryptographic primitives, and sports language enhancements like multiple inheritance and garbage-collected, anonymous objects.  On top of this platform, he built a simple, modern MVC web framework.  In the process, he learned quite a bit about maintaining, evolving, and extending old code, and about interacting with a small but passionate community of longtime users!  Sharing these learnings, rather than talking about the specific technical details, is the purpose of the presentation.

  47. (2014)  Lessons Learned from Implementing Real Life Whistleblowing Platforms  - Jurre van Bergen, Sacha van Geffen
    • Whistleblowers and online whistleblowing platforms have received quite a bit of attention recently.  Discussions range from the feasibility of implementing a sufficiently secure platform online for whistleblowers, to the changing role of journalism, to the ethics of whistleblowing itself.  The lessons learned from implementing multiple whistleblowing platforms in various contexts will be presented here.  The main experience is from Publeaks, a Dutch whistleblowing system based on the GlobaLeaks platform, launched in September of 2013.  (Publeaks now has almost all of the national press on board.)  The development of other leaking sites - like Wildleaks in Africa - will be discussed.  Globaleaks and SecureDrop will be introduced and compared.  The panel will reflect on social and legal challenges that your group might be facing if you try to implement a whistleblowing platform.  You will get some practical and theoretical insight into how you can create your own platform, whether for internal whistleblowing in an organization or for broad multi-stakeholder installations like Publeaks.

  48. (2014)  Lockpicking, a Primer  - Doug Farre, JGor, Babak Javadi, Ray, Jos Weyers, Deviant Ollam
    • If you're curious about what lockpicking is all about, this is the talk for you.  Several different ways of opening a lock will be shown (picking, bumping, snapping, key impressioning) and explained in detail.  No prior lockpick experience or knowledge is needed.  This talk will start at ground level.  Lockpicking has a clear analogy with the digital world (you have a firewall, therefore you are secure; it has a lock, therefore it must be safe).  Consider that physical access will, in lots of cases, render your digital security measures obsolete.  After this talk, expect to start rethinking your physical security.

  49. (2014)  Media, Popular Misconceptions, and the CSI Effect - What Does It Mean for InfoSec and Tech Policy?  - Sandy Clark (Mouse), Joshua Marpet
    • Forensics is tedious and occasionally mind numbing.  Exploit discovery and development is extremely detail oriented, and requires strong coding skills.  Good Blue Team defensive strategy and implementation is team based, precise, and careful.  But put a white lab coat on and, apparently, it's all magic!  From Abby's "It's commercial encryption, so it's cracked!" to CSI's famous, "Enhance!  Magnify!  Enhance!," the tropes of the popular entertainment world follow Arthur C. Clarke's famous saying "Sufficiently advanced technology is indistinguishable from magic."  So let's make all techs wizards!  How does this popular view of tech wizardry help our hacker world?  How does it hurt us, when we have to enter the courtroom, either as an expert witness, or as a defendant?  How can you, when put into one of these situations, defuse these tropes and make them work for you, or at least not hurt you?  Does this distorted world view hurt or help technical people, companies, organizations, and agencies, in the world of tech policy, governmental regulations, and National Security Letters?  Let's talk.

  50. (2014)  Movie: Algorithm  - Jonathan Schiefer
    • A feature-length movie about computer hackers directed by Jonathan Schiefer.  Running time: 91 minutes.
    • "The geeks have inherited the earth... the rest of you just don't know it yet."  In San Francisco, nine months before Edward Snowden leaked documents that prove the NSA spies on everyone, Will, a freelance computer hacker, specializes in breaking into secure systems.  During a job, he stumbles across a way into Emergent See, a top-secret government contractor.  Will downloads all of their recently developed software, including the conspicuously named Shepherd.  Every time Will attempts to access Shepherd, bad things happen, starting with his apartment burning down, kidnapping, etc.  Will makes it his mission to break into Shepherd and find out why someone is willing to go to such extremes to keep it secret.  Free vegan popcorn supplied by director Jonathan Schiefer, who will be on hand after the screening for a question and answer session followed by movie prize giveaways.
    • Trailer at: www.thehackermovie.com

  51. (2014)  Movie: Die Gstettensaga: The Rise of Echsenfriedl  - Johannes Grenzfurthner
    • A post-apocalyptic science fiction nerd agitprop comedy feature directed by Johannes Grenzfurthner.  Running time: 72 minutes.  Languages: English and German (with subtitles).
    • The growing tension between the last two remaining superpowers - China and Google - escalates in the early 21st century and results in the global inferno of the "Google Wars."  Civilization came to a grinding halt.  But there is still hope.  This is the story of a new beginning...  Furtherfield calls it "hackploitation, reimagining the makerspace as grindhouse."  Film Threat gave it 5/5 stars and calls it "the must-see indie of 2014."  Cory Doctorow praises it as "surpassing and delightful weirdness."  Jason Scott calls it "the best kind of low-budget filmmaking... it is like watching an absurdist play by Beckett, if Beckett decided to work on the Mad Max franchise."  Richard Kadrey thinks it is "a mad post-collapse satire of information culture and tech fetishism."  And Jens Ohlig (CCC, Wikimedia) says it's "impressive."  The film was co-produced by art tech group monochrom and the media collective Traum and Wahnsinn, and created for the Austrian television channel ORF III.
    • More info at: www.monochrom.at/gstettensaga

  52. (2014)  Movie: The Internet's Own Boy: The Story of Aaron Swartz  - Brian Knappenberger
    • A documentary directed by Brian Knappenberger Running time: 105 minutes.
    • The story of programming prodigy and information activist Aaron Swartz.  From Swartz's help in the development of the basic Internet protocol RSS to his co-founding of Reddit, his fingerprints are all over the Internet.  But it was Aaron's groundbreaking work in social justice and political organizing, combined with his aggressive approach to information access that ensnared him in a two-year legal nightmare.  It was a battle that ended with the taking of his own life at the age of 26.  Aaron's story touched a nerve with people far beyond the online communities in which he was a celebrity.  This film is a personal story about what we lose when we are tone deaf about technology and its relationship to our civil liberties.  Director Brian Knappenberger will be in attendance for a question and answer session after the screening.
    • Trailer at: www.takepart.com/internets-own-boy

  53. (2014)  Movie: War on Whistleblowers: Free Press and the National Security State  - Robert Greenwald
  54. (2014)  North Korea - Using Social Engineering and Concealed Electronic Devices to Gather Information in the World's Most Restrictive Nation  - Mark Fahey
    • North Korea prevents its citizens from accessing any form of independent media or information.  Any citizen who attempts to access foreign broadcasts to seek information from the outside world risks being interned in one of the state's notorious prison camps.  The very few visitors allowed into the country are strictly forbidden to bring any radios, GPS receivers, or other communications equipment.  As a result, little independent and objective information about the propaganda-based mass media of the country has been gathered and published.  Over four successive trips into each province of the DPRK, Mark has smuggled electronic equipment in and out to capture, monitor, record, and analyze hundreds of hours of local and regional domestic radio and television broadcasts used by the North Korean regime as a prime instrument of control over the population.  This will be a fast-paced interactive audio/visual presentation of rare video, audio, and still photography together with an explanation of the social engineering techniques he used to successfully travel throughout North Korea and covertly gather information with concealed electronic equipment.

  55. (2014)  Obfuscation and its Discontents: DIY Privacy from Card Swap to Browser Hack  - Daniel C. Howe
    • Data collection, aggregation, and mining have dramatically changed the nature of contemporary surveillance.  Refusal is not a practical option, as data collection is an inherent condition of many essential societal transactions.  In this talk, we discuss one response to this type of everyday surveillance, a tactic called obfuscation.  Tactical obfuscation can be defined as the strategy of producing misleading, false, or ambiguous data with the intention of confusing and/or inhibiting an adversary.  Because obfuscation is relatively flexible in its use by average citizens as well as by experts, it holds promise as a strategy for DIY privacy and security.  This talk presents a brief overview of obfuscation as political theory, including contemporary and historical examples, then focuses on two recent systems that address data collection: TrackMeNot, which shields searchers from surveillance and data profiling, and Ad-Nauseam, which targets advertising networks that track users across the web.  The talk concludes with a consideration of the ethics of obfuscation as representative of a class of strategies whereby weaker parties can both protect against and confront stronger adversaries.

  56. (2014)  Per Speculum in Ænigmate  - Maximus Clarke
    • In the fall of 2013, artist Maximus Clarke was inspired by news of government and corporate surveillance to create an art project about privacy that could also function as a secure messaging system.  The result is Per Speculum in Ænigmate - Latin for "through a glass darkly" - combining stereo imagery and PGP encryption.  Each project image is an anaglyph 3D photo of a nude model, obscured by pixelation and overlaid with an encrypted message sent by one of the project participants.  Message recipients are able to download images from the project site (psiae.tumblr.com) and decrypt the embedded texts, without the artist ever reading them.  This presentation will showcase the project images in glorious old-school red/blue 3D (glasses will be provided), and discuss the concepts, technologies, and processes involved in their creation.

  57. (2014)  Postprivacy: A New Approach to Thinking about Life in the Digital Sphere  - tante
    • The social construct of privacy is rather new, a result of the civil society.  It was supposed to protect people from the state and/or government and its overreach, a "right to be let alone," as one of the central legal texts defined it.  Privacy promised a safe space for the individual to develop new ideas without premature criticism and discrimination, a space where individual freedom unfolded.  Did it really deliver on that promise?  And was that the promise we needed as a society?  Privacy isn't dead as some people might want to tell you, but it has changed significantly in its definition, in its relevance.  And it no longer works as the central foundation of our social utopias.  Private people are alone, powerless, and often invisible when faced with exactly those powerful entities that the Internet was supposed to help us fight (corporations, government agencies, etc.).  Under the blanket term #postprivacy, some people have started developing ideas on how to rethink how we can harness not only the power of the Internet but the powers, ideas, and skills of each other.  How will we as a social structure work between social networks, government snooping, and encryption?  How can we save and form the future?  This talk will give you a few new ideas.
    • New York and HOPE X Summary

  58. (2014)  PRISM-Proof Email: Why Email Is Insecure and How We Are Fixing It  - Phillip Hallam-Baker
    • We have had the technology to make email secure against criminals and government spies for decades.  Microsoft, Netscape, and Apple have all shipped products with built-in encryption for over 15 years, yet almost nobody uses these features.  Millions of people were very upset by the recent Snowden revelations - why aren't millions of people using secure email and, more importantly, how do we fix it?  A part of the reason for the lack of email security is rooted in politics.  During the 1990s, cryptography rights activists battled with the NSA and FBI for the right to use strong cryptography, a series of events known as the cryptowars.  One part of the problem is that two email security standards emerged rather than one, neither of which is capable of fully replacing the other.  But the biggest part of the problem is that any system which requires the user to be thinking about security is too hard to use.  This talk will be looking at the history and future of email encryption technology.  No prior knowledge of cryptography will be assumed.

  59. (2014)  Privacy-Friendly Hypertext?  Do Not Track, Privacy Badger, and the Advertising-Funded Web  - Peter Eckersley
    • This talk will introduce the design and implementation of Privacy Badger, EFF's new browser extension that automatically blocks both invisible trackers and spying ads.  It is intended to be a minimal- or zero-configuration option that most Internet users can use to prevent nonconsensual third-party collection of their reading habits from their everyday browser.  Privacy Badger couples the recently developed HTTP Do Not Track opt-out header with a number of heuristics for classifying the behavior of third parties to automatically determine which should be blocked, which are needed but should have cookies blocked, and which are safe from a privacy perspective.  Peter will also talk about the bigger picture on the role that nonconsensual commercial surveillance has come to play in the business and technical infrastructure of the Web; and what we can do to build better alternatives.

  60. (2014)  Project PM: Crowdsourcing Research of the Cyber-Intelligence Complex  - Andrew Blake, Lauren Pespisa, Kevin Gallagher, Joe Fionda, Douglas Lucas
    • In April 2013, the FBI sought information on what the journalist Barrett Brown was doing with an open-source collaborative wiki that he founded called Project PM, and were equally as curious about what kind of dirt he had on his hard drives about the government contractors and intelligence firms he investigated on that site.  Edward Snowden's leaks about the NSA have since exposed only the tip of the iceberg with regards to how much the U.S. intelligence community is capable of, and those efforts are largely assisted by the likes of companies who Project PM set out to research: Ntrepid, Abraxis Hacking Team, Cubic, Endgame, Palantir, and others.  Now, more than ever, is the time to collect and analyze open-source information about the shadowy companies who operate on behalf of the U.S. government, often without being held accountable.

  61. (2014)  Reverse Engineering - Unlocking the Locks  - Matthew O'Gorman (mog)
    • If you can't tear it apart, drive it, or modify it, do you really own it?  This talk seeks to free a Kwikset PowerBolt and show you how to reverse engineer and take back control of your life.  The Kwikset PowerBolt lock has support for a Z-Wave module.  You will learn how to diagram the function of all the ICs on the Z-Wave daughter board and the Kwikset main board, how the interfaces are used across the board, how the components are connected to each other, how to spy on the traffic, and finally how to replace the Z-Wave module with your own daughter board created in gEDA.  This knowledge will give you the freedom to lock and unlock your front door in any way you can imagine.  This talk will teach you how to use a multimeter to test for continuity and voltage, a bus pirate to quickly test protocols, logic analyzer tools to sniff traffic on the board, and other electrical tools.  You will learn how to diagram a system at the flow chart and schematic level and best practices on how to learn a system.

  62. (2014)  Rickrolling Your Neighbors with Google Chromecast  - Dan Petro
    • Take control over your neighbors' TVs like in the movies!  The Google Chromecast is a handy little gadget that lets you stream video to your TV from a variety of sources like Netflix and YouTube.  It also happens to allow streaming from nearby hackers.  This talk will demonstrate how to hijack any Google Chromecast - even if it's behind a secure Wi-Fi network - to do your bidding.  A new tool will also be released to fully automate the hijacking and playing of arbitrary video to the victim's TV.  Let the prank war commence.

  63. (2014)  Screening: Nowhere to Hide  -
    • Working title: Rambam Gets His Man
    • The world premiere of the Investigation Discovery (ID) TV series, based on incidents surrounding the FBI arrest of Steve Rambam at HOPE Number Six.  It all took place at the Hotel Pennsylvania, shortly before his panel covering how to track down an evasive person.  (His talk was rescheduled by HOPE staff four months later at Stevens University to a standing-room-only audience.)  Charges were later dropped, then refiled by DOJ, then dropped again.  The lead FBI Special Agent on case was later arrested on 20 felony fraud counts.  This world premiere will be followed by a question and answer session featuring Steve Rambam and some of the people behind the series.

  64. (2014)  SecureDrop: A WikiLeaks in Every Newsroom  - William Budington, Garrett Robinson, Yan Zhu
    • SecureDrop is an open-source whistleblower submission system that media organizations can use to securely accept documents from and communicate with anonymous sources.  The platform has been deployed and is being actively used by an array of journalistic organizations to provide a secure and usable platform for whistleblowers to get in touch with journalists while protecting their own identity.  The talk will begin with a broad overview of the project and then go into more detail: what does the network architecture look like, what does it provide, and what cryptographic primitives are used?

  65. (2014)  Securing a Home Router  - Michael Horowitz
    • Routers sit between all your computing devices and the Internet, making them a perfect target for abuse (Glenn Greenwald has written about the NSA hacking into them).  The presentation will explain some of the configuration options in home routers that can make your Local Area Network more secure.  Among these are locking down access to the router, Wi-Fi security, firewalls, DNS, and hiding on the Internet.  Also covered are known security flaws in routers and how to defend against them.  Some of the covered flaws are: WPS, UPnP, port 32764, Heartbleed, and smartphones leaking Wi-Fi passwords.

  66. (2014)  Shortwave Pirate Radio and Oddities of the Spectrum  - Andrew Yoder
    • Radio has become marginalized and governments are curtailing international shortwave broadcasting, yet these bands remain one of the most anonymous and inexpensive ways to convey information within and across international borders.  This presentation will include background information about shortwave radio, its range, what types of stations are on the air (broadcast, military, weather fax, spy numbers, amateur, and more), and finally pirate radio.  It will include background information behind pirate broadcasting stations on the air, how stations attempt to maximize their signal quality and range while avoiding detection by the authorities.  Some of these tactics have ranged from transmitting from ships, to leaving battery-powered transmitters on public lands, to installing equipment at highway billboards.  In an age when IP addresses, GPS, and cell phones track people as well as data, pirate radio is one of the few means of sending untracked, anonymous information.

  67. (2014)  Showing Keys in Public - What Could Possibly Go Wrong?  - Jos Weyers
    • If a reporter wants to get the point across that certain people shouldn't have access to a particular key, would it be wise for said reporter to then show that key to the world?  Like the New York City subway key?  The key to the subway?  On the Internet?!  This and other media fails will be shown.  And maybe even one or two non-fail examples...  Several cases of key-copying-by-sight will be discussed with lots of pictures and videos.  How this can happen will be explained, as well as what to do to prevent it.

  68. (2014)  Skeuomorphic Steganography  - Joshua Fried
    • Skeuomorphic steganography is spawned in the terrain where art, code, and digital media interbreed.  Steganography is the ancient art, revitalized in the digital age, of hiding messages in plain sight.  Skeuomorphism is the use of design elements that include features inherent to an earlier design, for example, images of leather binding in on-screen calendars, or faux wood grain printed on vinyl tiles.  This talk puts forth the theory that steganography finds a natural home inside skeuomorphism.  Sometimes, when one is looking for hidden data, one has to know where to look.  This is especially true outside the digital realm.  An idea for a new convention will be proposed: Let's have skeuomorphism show us where to look.  Joshua will show how printed skeuomorphic steganography can be decoded with simple tools.  The dream is of a world, just slightly more fun than this one, in which skeuomorphism takes on a new life, not as kitsch, an eyesore, or some wigged-out aberration at Apple Inc., but as a hint of a possible invitation, a bread crumb left by a new friend.

  69. (2014)  Social Engineering  - Evil Corley and Friends
    • The tenth incarnation of this panel, which officially makes it a tradition.  One of our biggest draws, this session always delivers something memorable.  The panel will tell stories of the magic of social engineering, predict what may or may not be possible in the future, and make a few live attempts over the phone to gain information they have absolutely no right to possess.  Sometimes it works and sometimes it fails horribly, as is the very nature of social engineering.  You'll learn how to recover from being denied or busted and how to push forward, gaining tiny bits of information until you possess more knowledge about your target than you (or they) ever thought possible.

  70. (2014)  Solve the Hard Problem  - Gillian "Gus" Andrews
    • The biases run deep: from early in our school careers, we're taught that "smart people" go into math, science, and tech.  There's an unspoken hierarchy many of us have drilled into our heads, with particle physics at the top of the academic food chain, engineering lower down but still higher than that weird squishy stuff in biology and the even squishier stuff in sociology, etc.  "Smart people" tackle the "hard" problems, and the hard problems involve a lot of math, "hard" science, and empirical evidence.  Well listen, J. Random Hacker, if you're so goddamn smart, why haven't you built a tool that makes it easy for people to encrypt their email yet?  Why is adoption the major barrier to secure communications?  Why haven't the tools you've built evened out the digital divide?  Is the hard problem infrastructure scaling or the Traveling Salesman problem, or is the really hard problem dealing with the people you could never get to understand what you're doing?  This talk will be an exhortation for hackers to overcome the traditional biases many of us have in favor of technical projects and against human-factors work.  It's a call for more people to think about usability in open-source software, particularly on the privacy and security tools we care so much about.  Gus will tease apart the deep-seated socialization we have about what work "smart" people do, what "good" science looks like, and why studies of human social interactions must have different criteria than "hard" sciences in order to be effective.

  71. (2014)  Spy Improv: Ask Me Anything - Part 1  - Robert Steele
    • Spy Improv: Ask Me Anything - Part 2
    • The former spy, honorary hacker, former candidate for the Reform Party presidential nomination, and #1 Amazon reviewer for nonfiction, again takes on any question.  His record, set in 2010, is eight hours and one minute.  This year, the formal program provides for two hours.

  72. (2014)  SSL++: Tales of Transport-Layer Security at Twitter  - @jimio
    • You've enabled HTTPS on your site.  Now what?  How do you protect against sslstrip attacks, CA compromise, and the dangers of mixed content?  @jimio will share some approaches they've taken @twitter: Strict-Transport-Security, "secure SEO" with canonical link elements, Content Security Policy, and certificate pinning.  There will be code, exploits, and open-source!  There will be a few fun stories to share as well, and since this is an SSL talk, you KNOW there's gonna be Heartbleed.

  73. (2014)  Steepest Dissent: Small Scale Digital Fabrication  - Nadya Peek
    • High precision in fabrication is often required for building useful hardware and tools - including hardware and tools that can be used for dissent.  Craftsmanship is valued for its precision and attention to detail, but mastering a craft is inherently slow.  3D printers evoke a Star Trek replicator-esque, hands-off solution for instantly creating precise tools, but in that image also become a transparent technology.  However, digital fabrication technology as it exists today is anything but transparent, as digital fabrication tools are difficult to access, interface with, modify, and even use as intended.  In a way, lack of access to precision fabrication is in itself a form of control.  This talk will be about how digital fabrication enables personal fabrication, and how we are getting closer to being able to truly use digital fabrication in technologies for dissent.

  74. (2014)  Stupid Whitehat Tricks  - Sam Bowne
    • How can you improve security at companies that haven't hired you or given you permission to test their systems?  Non-intrusive methods such as Google searches and observing headers can detect some serious problems without trespassing on networks.  Sam found problems at thousands of websites, including dozens of companies and big-name colleges that are currently under hostile control.  These problems included SQL injections, website redirectors, WordPress pingback exploits, and more.  Many of the systems were being used by criminals to perform attacks.  He notified the companies.  Most ignored the notifications.  Some of them fixed the problems, a few complained, and one made a serious effort to silence him.  In this talk, Sam will show how he found the problems, how he notified the administrators, and how they reacted.  Whitehatting can be useful and rewarding, as long as you have realistic expectations and a thick skin.

  75. (2014)  Surveillance, Sousveillance, and Anti-Surveillance: Artistic Responses to Watching  - Gregg Horton
    • It's impossible to imagine a world without surveillance.  Its presence reflects a symbiotic relationship with the State and hegemony as a whole.  For years, artists have been using surveillance and surveillance technologies to engage and disrupt the surveillance apparatus.  This talk will explore works by artists such as Steven Mann, (((Banksy))), The Surveillance Camera Players, and many more working in the medium to answer the question of "How are we to engage with a surveillance society?"
    • AI Transcript

  76. (2014)  Teaching Electronic Privacy and Civil Liberties to Government  - Greg Conti
    • Privacy advocates and government officials are often at odds.  Ironically, both groups want the same thing - a safe and free democracy.  This will be an exploration of how government employees can better make protection of privacy and civil liberties part of the calculus considered when making security decisions - not just due to legal compliance constraints or fear of a backlash from privacy advocates, but due to a true appreciation that privacy and civil liberties are as important to democracy as is security.  This talk will cover initial successes in exposing government employees to electronic privacy and civil liberties material in the classroom, and sketch the outlines of open-source training materials.  The ultimate objective is to inform and inspire government employees worldwide to propagate legal reform inside the system without taking extreme approaches.  The presentation will be interactive, so please come with ideas for content and educational strategies that might be used to educate government employees at all levels and in a wide variety of countries on the importance of electronic privacy and civil liberties.
    • Slides
    • AI Transcript

  77. (2014)  Technology and Jamming of XKEYSCORE  - Robert Graham
    • XKEYSCORE is possibly the most "Big Brother" tool in the NSA arsenal, eavesdropping on network traffic around the world producing around 100 billion records per month.  Recently, code snippets were leaked, allowing us deeper insights into how the system works.  This talk will be in three parts.  The first part will be an overview from what we know from public disclosures, how the packet sniffer reads network traffic and indexes it for automated systems and human analysts.  The second part will walk through the disclosed source code, comparing it to public deep-packet inspection tools, in order to get a detailed understanding of the internals.  The third part will look at jamming the system, both the specific fingerprints in the disclosed source code, but also other fingerprints that might exist.  The unexpected ways that the source may indirectly run afoul of FISA regulations will also be investigated.  Questions from the audience are encouraged.
    • AI Transcript

  78. (2014)  The Hidden World of Game Hacking  - Nick Cano
    • A common misconception in the world of online gaming is the idea that the only game you can play is the one in the title.  Contrary to this, game hackers find enjoyment playing the game that hides behind the curtain: a cat-and-mouse game of wits between game hackers and game developers.  While game hackers work to reverse engineer game binaries, automate aspects of game play, and modify gaming environments, game developers combat the hacker-designed tools using anti-reversing techniques, bot detection algorithms, and heuristic data-mining.  This talk highlights the fight put up by game hackers, and the advanced methods they have engineered to manipulate games while simultaneously eluding game developers in the dark corners of their own software.

  79. (2014)  The Internet Society Speaks - The History, Futures, and Alternate Directions of the Internet and Its Governance  - Jeremy Pesner, David Solomonoff
    • In 1992, TCP/IP co-inventors Vint Cerf and Robert Kahn founded the Internet Society, instilling their belief that "the Internet is for everyone" into the policies and operations that the institution has championed ever since.  The Internet Society has become the de-facto organization that maintains attention and lobbies on behalf of the public interest on all issues of Internet policy.  Thanks to SOPA, Snowden, and the recent FCC rulings, issues of Internet policy are now very much in the public eye, but certain details have been misunderstood or misrepresented in the frenzy of discussion and reports.  This talk by members and employees of the Internet Society will help to inform and educate HOPE attendees, providing them a solid knowledge base and history of Internet policy to work from.  The three panelists each maintain different areas of expertise within the field of Internet studies: Jeremy has researched and written on the early history of the Internet's development and the policies discussed by the Clinton administration that brought the technology into everyday use; David has long been active in grassroots Internet efforts and can speak to some of the less traditional perspectives on Internet governance; Avri will speak to the worldwide governance efforts and the deliberations around the Internet among several countries.  The panel will examine the history of the Internet, the policies around it and some of the key initiatives it has helped to spark.
    • AI Transcript

  80. (2014)  The Many Faces of LockSport  - Doug Farre, JGor, Babak Javadi, Ray, Jos Weyers, Deviant Ollam
    • In the past decade, the hacker subculture of LockSport has seen a tremendous explosion.  What was once the purview of dedicated specialists, far-flung hobbyists, and college students meeting in secret is now featured prominently at technical conferences, family-oriented science fairs, and even TV shows.  The Open Organisation Of Lockpickers (TOOL) now has nearly 20 chapters across the Netherlands, the United States, and Canada.  Sportsfreunden der Sperrtechnik is still going strong with hundreds of members.  LockSport International has meetup groups in major cities.  Regional groups like the Fraternal Order Of LockSport, the Longhorn Lockpicking Club, the FALE Association of LockSport Enthusiasts, and more conduct local meetings and engage in joint ventures with larger organizations.  At the annual LockCon conference, sport pickers from over a dozen countries gather to learn from one another and compete head to head.  Despite the shared interest and community between all LockSport groups, there is great variation between the cultures and values of these participants.  This panel discussion will feature some of the key figures from various locksport organizations around the world and will hopefully highlight some of those differences and offer the audience a chance to ask questions about locks, LockSport, and competitive lock-opening.  (A primer on basic lockpicking and lock-opening techniques will be offered very quickly at the start of the session if you've never learned these kinds of skills before!)

  81. (2014)  The Repair Movement  - Sandra Goldmark, Vincent Lai, Miriam Dym, Tiffany Strauchs Rad
    • Mending (or fixing/repairing) - part of the spectrum that includes hacking, alteration, and making - can become a political act in a time of cheap goods, outsourced labor, and low wages.  What is mending's role in a new model of production and consumption, one where artisans and individuals face off, perhaps quixotically, against mass production?  Can repair become economically viable?  How does mending contend with goods that are poorly made in the first place, when globalization undermines local resources, when companies design objects AND supply chains to be repair-resistant?  Panelists from the repair movement will discuss the opportunities as well as the barriers to making repairs in the human realm: social (habits and systems), economic (prices, labor), and technical (parts, design).  Repairing things, rather than discarding or putting up with broken objects or systems, connects deeply to the hacker/maker movement and to sustainable ecology.  Panelists will address how repair can be beautiful as well as potentially disruptive.  This panel includes activists and artists, attorneys and organizers - drawn to repair as process and performance.  An act of repair has the possibility of political significance or an act of resistance, and brings the possibility of transformation to ordinary objects and larger systems alike.
    • AI Transcript

  82. (2014)  The Science of Surveillance  - Jonathan Mayer
    • The National Security Agency is bound by legal constraints.  It hasn't always followed the rules, to be sure.  But when it does, are constitutional and statutory safeguards effective in protecting our privacy?  This talk presents empirical computer science research on the NSA's legal restrictions, including results cited by President Obama's intelligence review group.  We find that present limits on bulk surveillance programs come up far short.  Authorities intercept international Internet traffic and enable the monitoring of ordinary Americans' online activities.  The domestic telephone metadata program reaches much of the population, and allows for drawing extraordinarily sensitive inferences about medical conditions, firearm ownership, and more.

  83. (2014)  The Sex Geek as Culture Hacker  - Kristen Stubbs
    • "Being a nerd is not about what you love; it's about how you love it."  Wil Wheaton's words ring true for many self-identified geeks and nerds.  But what happens when what you love is "love," or even "lust?" Geeks have never been more cool, but mainstream culture is full of negative messages about sex and pleasure.  Combining nerd enthusiasm and geek know-how with erotic experiences results in writings, DIY toys, citizen science, and other projects which can promote sex-positivity and consent culture.  In this talk, Kristen "Where did this b!tch get her doctorate" Stubbs shares stories from the sex geek trenches: the awesome, the awkward, and the randomness in between.

  84. (2014)  The Web Strikes Back - Fighting Mass Surveillance with Open Standards  - Harry Halpin
    • After the Snowden disclosures, it was revealed that the NSA and NIST were subverting the open standards process by intentionally weakening the security of the core standards that form the foundation of the web and Internet.  Now, more than ever, we need cryptographically strong standards and verified open-source libraries for these standards.  The humble origins of the IETF and the W3C will be discussed, as will the efforts taken by open standards to combat pervasive surveillance via workshops like STRINT and the "perpass" mailing list, and the new standardization work that is likely to result.  In particular, the focus will be on the myriad problems implicit in putting cryptography into the web security model with the W3C Web Cryptography API, as well as attempts to analyze properties of this JavaScript API by using techniques from formal proof-proving.  There's also new work from the W3C on decentralized social networking - and all the security problems that entails!  Most importantly, you'll learn how you can get involved to help build open standards to build what Tim Berners-Lee calls the "Web We Want" - and stop the web from being subverted.

  85. (2014)  This Is the X You Are Looking For  - Eric Davisson (XlogicX)
    • When you hear you are being profiled for which books you check out in a library, what do you do with this knowledge?  Do you tell your friends to "evade," to not check these books out, or to find other means of getting this content?  No.  You tell everyone in the world to deliberately check these books out (and now we have had the pleasure of reading Catcher in the Rye).  This talk is about looking signature detection in the face and confusing or saturating the tool or analyst.  A number of techniques will be explored, including a fun malware signature trick called a tumor (it's OK, it's benign), and others focusing on open-source Intrusion Detection Systems.  There may be some random banter about grocery loyalty cards, too.  Although this talk intends to be just as technical as expected at a conference like this, it will also be light, fun, and philosophical in nature.  Expect a gratuitous slide deck, lots of terminal action, signatures in the nude, hex, and beautiful regex.

  86. (2014)  Threat Modeling and Security Test Planning  - Eleanor Saitta
    • How do I figure out if the application I've designed is secure?  What do I need to test?  When do I need to start thinking about security?  How does what an application is designed to do affect how it's tested?  How do high-level security goals relate to protocol bugs?  How do I know when I need specialist review?  How do I figure out if my users will be able to use my application securely?  If you've found yourself asking questions like these or if you're just realizing that maybe you should be asking them, this talk will give you tools to work with.  The work that a security analyst does can be opaque, but understanding it will save you time and help you build a more secure application.  This talk will cover threat modeling (both on its own and as a driver of high- level test planning), when and which kinds of low-level tests you should be including, with special attention paid to parser/protocol bugs.  Examples will be shown from both the commercial space and the world of software designed for high-risk users, with specific focus on some of the particular challenges of the latter arena.
    • Slides
    • AI Transcript

  87. (2014)  Thwarting the Peasants: A Guided and Rambunctious Tour Through the 2600 DeCSS Legal Files  - Jason Scott
    • In 2000, a whole lot of movie companies sued a whole lot of people over the coding of a routine called DeCSS, which would allow the access and playback of DVDs in Linux and any other platform that felt the burning desire to watch Hollywood movies.  The full name of the court case has a name too long for this description, but by the time it was over, a whole host of individuals had dropped out, leaving 2600 Magazine and the rest fighting over the point of whether linking to infringing materials is itself infringement.  The case was decided in Hollywood's favor, and passed into the realm of history.  A decade later, the extensive files related to this case were slated for disposal, and Jason Scott volunteered to take possession of them.  These files are now being scanned in, and contain all manner of amazing material, some highlights of which will be shown in this presentation.  The case was a time capsule of an industry expecting yet another rolling over of the populace as to who truly owned the media.  It didn't quite work out that way.  Expect a level of excitement not usually found in court transcripts and evidence collections.

  88. (2014)  Travel Hacking with The Telecom Informer  - TProphet
    • When people talk to TProphet (also known as The Telecom Informer) about how he travels and lives all over the world, experiencing destinations from Armenia to Antarctica, they often say something like "I could never afford that!" If you think like a hacker, though, travel doesn't have to be expensive.  You will learn how tickets for an around-the-world trip were booked for under $219, and how you can also travel for little or nothing.  The world is an incredible place to explore.  This talk will encourage you to get out and see it!
    • Seat 31B

  89. (2014)  Unmasking a CIA Criminal  - Ray Nowosielski
    • "Her name is Alfreda Frances Bikowsky."  While those six words may seem innocuous, according to the Central Intelligence Agency, if made publicly, they might have sent Ray and his journalist colleagues to prison.  On September 8, 2011, they received the first in a series of phone calls and emails from CIA's media rep Preston Golson.  "We strongly believe it is a potential violation of federal criminal law [the IIPA Intelligence Identities Protection Act] to print the names of two reported undercover CIA officers whom you claim have been involved in the hunt against al Qa'ida."  They had used this approach successfully several times in the past to persuade some of America's most respected journalists - (((Jane Mayer))) of The New Yorker, (((Adam Goldman))) and Matt Apuzzo of the Associated Press, among others - to withhold her name from the public.  Seeking advice from the ACLU's National Security Project, its lead attorney (((Ben Wizner))) made them aware that she had become something of an open secret in his world.  They had stumbled onto a hornet's nest.  Bikowsky, as it turned out, was the person credited internally with the greatest PR coup of the Obama White House, the successful assassination earlier that year of Osama bin Laden.  As chief of the Global Jihad Unit, she reportedly runs the nation's drone strikes program.  She is a through-line running from the failure to prevent 9/11 to the push for war in Iraq to the development of the CIA's renditions, black sites, and torture program and continuing to today's targeted assassinations in countries around the world.  Through her story, we can see the details of a devolution in the rule of law and the justice system in America, as well as the impetus for and birth of what some call the "war on whistleblowers and journalists."  For 20 years, she has been at the center of history, yet the covert nature of her job has prevented that history from ever before being told to the public in one place.  Doing so is necessary for a democratic citizenry to have an informed discussion about national security and intelligence policy in America's continuing fight against terrorism.

  90. (2014)  Updates from the Online Identity Battlefield  - aestetix, Kaliya "IdentityWoman"
    • At HOPE Number Nine, aestetix gave a general introduction to the world of nyms (short for pseudonym) and NymRights (the group he created to promote online self-expression).  Things have changed a lot in the last two years.  More services are moving online, and there are a lot of discussions about how to securely "verify" users, how to prevent fraud/ harm, and how to do all of this while keeping our civil liberties intact.  There have also been developments with the National Strategy for Trusted Identities in Cyberspace (NSTIC), an Obama strategy designed to promote these discussions in places like health care and social security.  The White House is finalizing points on their Cybersecurity Framework (which includes NSTIC) and, in the meantime, a bunch of web services are implementing "verification" solutions, some with better success than others.  In light of fundamental "nym" ethics, the discussion will take a look at these strategies and solutions, show which work better than others and why, and introduce some things the panelists have been working on as well.

  91. (2014)  Usable Crypto: New Progress in Web Cryptography  - Nadim Kobeissi
    • This talk will provide an outline of the pitfalls, dangers, benefits, and progress when it comes to doing encryption in JavaScript in the browser.  Nadim has been working on this problem for the past three years in collaboration with Mozilla, Google, and the W3C.  The solution is still far away, but there have been many interesting (and, most importantly, educational) challenges that have been faced.  After giving an overview of how browser cryptography has advanced in the past year, Nadim will reveal a new open-source encryption software project during the talk.

  92. (2014)  Using Travel Routers to Hide in Safety  - Ryan Lackey, Marc Rogers (CyberJunky)
    • In light of the past year's NSA revelations and the long history of SIGINT, safe network use is a serious concern, especially for international travelers.  Open-source and commercial tools to hide one's identity when traveling will be described here, in the face of both blanket surveillance and targeted, intense monitoring.  You will learn about tools which can be comfortably taken through restrictive border regimes and carried openly in war zones without attracting undue attention - as would suit a journalist or human rights worker.  While these tools tend to be complex, the true challenge is the threat model: a single slip-up, undetected at the time, can doom the user and the user's contacts to discovery, interrogation, or worse.

  93. (2014)  Vigilante Justice: Masks, Guns, and Networks  - Zimmer Barnes
    • This talk will cover the state of vigilante action around the world; what they fight with, who their targets are, how they stay anonymous, and how they organize.  Without condemning or condoning any single act, these radically unique responses to crime and corruption deserve our attention.  How much power are they wielding?  Is nonviolence winning out over violence?  Is anonymity giving way to irresponsible action?  And what should we expect as these networks deepen?  There's a growing list of options being explored, and these explorers have dramatic and largely unknown stories to tell.

  94. (2014)  Visualization for Hackers: Why It's Tricky, and Where to Start  - Tamara Munzner
    • Computer-based visualization systems provide visual representations of datasets designed to help people carry out tasks more effectively.  Visualization is suitable when there is a need to augment human capabilities rather than replace people with computational decision-making methods.  The design space of possible vis idioms is huge, and includes the considerations of both how to create and how to interact with visual representations.  Vis design is full of tradeoffs, and most possibilities in the design space are ineffective for a particular task, so validating the effectiveness of a design is both necessary and difficult.  Vis designers must take into account three very different kinds of resource limitations: those of computers, of humans, and of displays.  Vis usage can be analyzed in terms of why the user needs it, what data is shown, and how the idiom is designed.  Tamara will discuss the implications of all this trickiness for systems visualization, where the datasets include trace logs, network traffic, and semi-structured text in addition to the classic big table of numbers.  One good way forward is to think hard about how to transform your original data into a form that's well suited for addressing the user's problems before you dive into the details of exactly how to draw any pictures.

  95. (2014)  When Confidentiality and Privacy Conflict  - Daniel Kahn Gillmor
    • We have many mechanisms to provide confidential communications so that network operators and other would-be surveillance regimes can't inspect the content of our traffic.  But some of those mechanisms actually reveal more about who is speaking than cleartext communication would, especially over longer periods of time and large datasets.  Information about who is speaking to whom is so valuable that large organizations devote huge amounts of resources to assembling network graphs of this "metadata," even without the content of the communications.  Clearly this information is worth something; it is probably worth protecting.  Why should privacy (hiding who you are) conflict with confidentiality (hiding what is being said)?  This talk will look at specific instances of privacy and confidentiality conflicts, and describe patterns that create this tension.  There will also be a discussion on some approaches to resolve the conflict and outline ways to improve privacy while preserving confidentiality.

  96. (2014)  When Whistleblowers Are Branded as Spies: Edward Snowden, Surveillance, and Espionage  - Jesselyn Radack
    • When The Guardian and Washington Post published the first stories exposing the National Security Agency's surveillance operations based on revelations from the whistleblower Edward Snowden, the world learned that U.S. government officials told a series of misleading half-truths and outright lies to conceal what has become a U.S. surveillance industrial complex.  The revelations revealed massive waste, fraud, abuse, illegality, and an equally massive loss of valuable intelligence.  In response to the understandable public outrage about their mass surveillance, the NSA chose not to investigate the officials who needlessly and in secret sacrificed the privacy of hundreds of millions of innocent people.  Rather, the intelligence community has spent untold resources investigating and attempting to discredit Snowden.  It is a predicable response for an institution to focus on the messenger rather than the message.  It can be an effective distraction to focus the media and public attention on one individual rather on exposing systematic, widespread illegality in a powerful government agency.  Whistleblowers in all corporate and government spheres risk choosing their conscience over their careers, but under the Obama administration, national security and intelligence whistleblowers face choosing their conscience over their very freedom.  The Obama administration has prosecuted more people under the Espionage Act for alleged mishandling of classified information than all past presidential administrations combined.  The Espionage Act is an arcane, vague, and overbroad World War I-era law intended to go after spies, not whistleblowers.  NSA whistleblower Thomas Drake objected to mass surveillance using internal channels and was charged under the Espionage Act.  Central Intelligence Agency whistleblower John Kiriakou objected to torture and was charged under the Espionage Act.  He is now serving 30 months in prison.  Army Private Chelsea Manning helped expose war crimes and is serving 35 years after facing Espionage Act charges.  Because of this pattern of persecution, Edward Snowden was forced to leave the United States and seek asylum in Russia after the U.S. government left him stranded in the Moscow airport last year.  This talk, by a member of Snowden's legal team, will address all of this and more.

  97. (2014)  When You Are the Adversary  - Quinn Norton
    • If your name isn't Barton Gellman, Laura Poitras, or Glenn Greenwald, chances are that while the NSA may be a rights-violating threat to all, it's not your actual, day-to-day adversary.  Real world adversaries tend to be spouses, parents, bosses, school administrators, random drive-by malware, and maybe local law enforcement.  While federal threats create a terrible security culture, they aren't stepping into the lives of most people.  And while obsessing over various intelligence agencies and trying to build tools against them makes you feel like a badass, it doesn't help most people.  Fixing Flash and building easy to use communication tools does change the lives of countless people.  This talk will focus on the infosec needs of the 99 percent - who aren't geeks.  This talk will touch upon the value of bad crypto when it lets someone escape an abusive spouse, and the common situations where tools that let people sidestep the requirements of their IT departments make the world a better place.  Yes, the big bad guys still matter, but fighting a billion little bad guys probably matters more.

  98. (2014)  Why the Future is Open Wireless  - Adi Kamdar, Nate Cardozo, Ranga Krishnan
    • How do we begin the movement to create a world of ubiquitous open wireless, where sharing and openness is the norm?  How do we get it to spread?  Speakers from EFF's activism, legal, and technology teams will describe the open wireless movement (openwireless.org) and the specific challenges their open wireless router campaign is solving.  The first hurdle is convincing the world that sharing Wi-Fi with guest users is, as security expert Bruce Schneier puts it, a matter of "basic politeness."  Another perceived roadblock is the belief that running an open network could subject the host to legal liability.  Lastly, even proponents of open wireless lack easy technical solutions to safely enable private and anonymous guest access without reservations.  To that end, EFF is developing an easy to set up, secure Wi-Fi router.  But, in order to truly realize our open wireless future, they will need your help.

  99. (2014)  Will It Blend?  How Evil Software Clogs the Pipes  - Michael Sikorski
    • During an investigation, Michael discovered an attacker who was emailing himself from an infected user's account.  He sent and received emails under the radar via Outlook extension malware.  Countless times Michael has seen attackers forced to blend their malware communications with the noise on his clients' networks.  The talk will start with a brief history lesson on malware and its use of the network for command-and-control and data theft.  Then there will be some fun opening his malware vault to explore interesting specimens from the wild such as the Outlook Assistant and malware that tweets!  The presentation will close by discussing how you can find and analyze malware that communicates on the network and why traditional network monitoring isn't enough - attackers will find a way out of your network no matter how small a funnel you put them through.

  100. (2014)  Wireless Meshnets: Building the Next Version of the Web  - Kevin Carter, Peter Valdez, Kurt Snieckus
    • This panel will feature discussion and debate about the exciting current state of wireless meshnet technology, with a particular focus on how to build and join local urban wireless networks separate from the traditional Internet.  A short tutorial of the project as well as how to connect to a local meshnet - including an overview of the necessary open hardware and software required - will be provided at the beginning of the panel.  After the tutorial, a discussion will occur regarding the scope and impact of the global meshnet project.  Technology covered will include the CJDNS project, Hyperboria, installing the Meshberry image on a Raspberry Pi device, configuring Ubiquiti NanoStation M5 routers featuring the OpenWrt software, and other relevant topics.  Whether you're a new user or an enthusiast, this is a great place to learn more about the technology driving new free and secure private networks.

  101. (2014)  You've Lost Privacy, Now They're Taking Anonymity (a.k.a. Whistleblowing is Dead - Get Over It)  - Steve Rambam
    • Government and private entities are working to shred privacy and warehouse personal, relationship, and communications data.  Once unimaginable surveillance technologies are being perfected and implemented.  The most intimate details of lives are routinely and unthinkingly surrendered to data-gatherers.  Is it still possible to be an anonymous whistleblower?  Is it still possible to be anonymous at all?  Your physical location and activities for the past ten years are known and have been logged.  If you attend a church or synagogue or mosque or a demonstration or visit an abortion clinic or a "known criminal activity location" or meet with a "targeted person" or a disliked political activist, it is routinely recorded.  Your finances, sexual orientation, religion, politics, habits, hobbies, and information on your friends and family are gathered, indexed, and analyzed.  Facial recognition, camera analytics, license plate readers, and advances in biometrics allow you to be de-anonymized and remotely surveilled 24/7/365 by machines.  Forensic linguistics, browser and machine fingerprinting, and backdoors substantially eliminate the possibility of anonymous Internet activity.  Thanks to "The Internet of Things," your thermostat and electric meter report when you arrive home and your garbage can reports when you throw out evidence to be collected by the few remaining human agents.  "Predictive profiling" even knows what you will do and where you will go in the future, so the data collection bots can be waiting for you.  Data collection now begins at birth.  And no data gathered will ever be thrown away.  And none of the data gathered belongs to you or will be under your control ever again.  An internationally-known private investigator and longtime HOPE speaker, Steve will describe in frightening detail how the last shreds of everyone's anonymity are being ripped away.  Real world examples will be used.  Surprises can be expected.

  102. (2014)  Your Right to Whisper: LEAP Encryption Access Project  - Micah Anderson
    • The LEAP Encryption Access Project is dedicated to giving all Internet users access to secure communication.  Their focus is on adapting encryption technology to make it easy to use and widely available.  Like free speech, the right to whisper is a necessary precondition for a free society.  Without it, civil society languishes and political freedoms are curtailed.  As the importance of digital communication for civic participation increases, so too does the importance of the ability to digitally whisper.  When you attempt to secure your communications online, you are faced with confusing software, a dearth of secure service providers, and involuntary leakage of critical information.  For aspiring service providers, barriers to entry include the high cost and technical complexity of setting up secure servers.  LEAP's goal is to transform secure online communication from an exercise in frustration into an automated and straightforward process for those whose access to information and free expression depend upon confidentiality, authenticity, and the protection of their social networks.  Come to this talk to hear about LEAP's unique strategic infrastructure approach taking federated standards and open protocols to tackle these problems and find out how you can too.  Also, there will be pretty pictures of birds.

  103. (2014)  Closing Ceremonies  -
    • Every year, people make the same mistake.  They book their return trips too early on Sunday.  If you've done that this year, we encourage you to pay whatever the fee is to change your ticket and stick around.  The HOPE closing ceremonies are always a blast, as well as an opportunity to win lots of cool prizes that we have accumulated over time.  We'll also wax sentimental about how we (hopefully) managed to pull off yet another one of these events.  So stick around Sunday evening.  Think of Monday as a holiday - and beg forgiveness on Tuesday.



The Eleventh HOPE





  1. (2016)  Won't Somebody Please Think of the Journalists?  - Tom Lowenthal
    • You'll never believe this one weird trick that lets you flip the script on mass surveillance.  Oppressive institutions hate it.  In this call to arms, we'll learn how to change up debates about secure software and fight calls for backdoors more persuasively, as well as develop a way of thinking about building and supporting tools which really serve people's security needs.  The trick?  Think (and talk) about journalists.

  2. (2016)  When Video Is Not Standard Output  - XioNYC
    • In a GUI-dominated cyberspace, the blind user is prey.  When a UX change can mean the difference between productivity and disenfranchisement, when an interstitial scareware alert is indistinguishable from a legitimate error dialog, and when security cannot be established because accessibility is left to the aftermarket, the frustrating onus upon a non-visual user exceeds the empowerment the sighted user takes for granted.  This talk will shed light on some of these invisible "gotchas."

  3. (2016)  How to Start a Crypto Party  - Comet Crowbar
    • Learning about encryption tools can be intimidating.  If you don't feel comfortable with a computer, or are deathly afraid of some long-winded mansplaining of how something works, it's probably a nightmare or doesn't feel worth doing at all.  And who cares about combating NSA surveillance when you get frustrated/annoyed at "all this computer stuff?"  Enter the Crypto Party: a nonhierarchical space to get together and ask questions, learn from each other, and ideally to leave the event with encryption and anonymity tools set up on your computer.  It's a space to eat snacks, get answers, and, if no one knows, you can figure it out together.  There are solutions to resist surveillance, but it is still a problem of accessibility to get the solutions to the people in a way they can understand.  And there are already enough borders in this world!  In this talk, Comet Crowbar will share her experience with organizing monthly crypto parties in the Boston area.  Having been "crypto-ized" while living in Berlin, she was inspired by the do-it-yourself crypto parties she encountered there, and has aspired to bring the idea back to occupied Turtle Island.  And so far, so good.  Comet will also show examples of her zines and artwork that she uses as a medium to bring political issues to the mainstream by creating culture.  Become the media!  And start a crypto party in your hometown.  This talk is for everyone and will be using accessible language.

  4. (2016)  What is a 'Neutral Network' Anyway?  An Exploration of Net Neutrality  - Jeremy Pesner, Kate Forscey, Bob Frankston, Sam Gustin, Alfredo Lopez, Jesse Sowell
    • This spring, the FCC's net neutrality rules were upheld in court, giving the commission license to regulate the Internet as a public utility and ensure that all users are treated fairly.  However, the question remains as to exactly how net neutrality should be implemented and how well the concept applies to not only the Internet of today, but tomorrow.  Panelists will discuss the tensions between applying the idea of net neutrality to the pragmatics of the Internet's operations and the very real social and policy consequences of such decisions.  By combining and contrasting legal, activist, technical, journalistic, and academic perspectives, they will dig deep into the thoughts and aims behind net neutrality and derive a more nuanced and effective assessment of what is needed to create an Internet that works for everyone.  The panelists have discussed, taught, and deliberated these issues in university, government, and social settings, and boast employment/affiliations with MIT, Harvard University's Berkman Center for Internet and Society, ACM, IEEE, Columbia University's School of Journalism, VICE Media, May First/People Link, and Public Knowledge.

  5. (2016)  Water Security: Are We in De-Nile or In-Seine?  - Chris Kubecka, Lisha Sterling
    • The backbone of a modern society is clean, available water.  Without clean water, production plants falter due to corrosion, lack of cooling capability, or unsteady supply.  However, in many if not most parts of the world, water safety is a challenge.  This presentation gives an introduction to some of these challenges, trying to ensure clean, available water and the consequences of unfiltered, dirty water.  The focus is on what you can do to help solve this challenge.  You, the technologist, the hacker, the lockpicker, the everyday person, can help devise better systems to solve some of these challenges.  Geeks Without Bounds works around the world setting up solution-oriented hackathons that put participants in the driver's seat working together on technology issues to make the world a better place.

  6. (2016)  Security Options for High Risk Travelers  - Ryan Lackey
    • Aggressive surveillance and espionage has long been a fact of life for government agents traveling to hostile nations but, increasingly, economic espionage is waged against visitors who neither have the expectation that they're a target nor the resources to adequately defend themselves from plausible threats.  This talk will present tools, techniques, and procedures which will allow non-nation-state international travelers to defend themselves from government, criminal, and commercial monitoring, with a bias toward free and open-source options readily adopted by potential targets.

  7. (2016)  The Mathematical Mesh and the New Cryptography  - Phillip Hallam-Baker
    • Recent events have reminded us again of the urgent need to make encryption ubiquitous on the Internet.  Yet, with the exception of Transport Layer Security, encryption remains the domain of "expert" users.  HOPE X (2014) was held in the immediate aftermath of the publication of the Snowden papers.  In the two years since, there have been many important developments in the standards world (in particular, IEEE, IETF, W3C) that are designed to defeat mass surveillance.  These efforts include randomized MAC addresses for Wi-Fi, Certificate Transparency, and DNS privacy.
    • This talk will review those efforts and provide a preview of the next generation of cryptographic applications currently being built.  The PrismProof email system described at HOPE X has become the core of the Mathematical Mesh, an infrastructure that solves the encryption usability problem.  Once a device is connected to a user's Mesh profile, all the network application settings (including for OpenPGP, SSH, etc.) are managed automatically from an application controlled by the user.  Solving the usability problem and the current move to elliptic curve based cryptography allows Internet security to move beyond the limited cryptographic primitives used in TLS, SSH, and OpenPGP.  Public-key encryption offers more than just encryption and signatures.  Future message encryption schemes will allow end-to-end secure communication within groups of users without the sender having to create decryption material for each intended recipient.

  8. (2016)  Privacy Badger and Panopticlick vs. the Trackers, Round 1  - William Budington, Cooper Quintin
    • Increasingly, as you navigate the web, your movements are being tracked.  Even when you reject browser cookies, you transmit unique information that makes your browser personally identifiable.  Ad tech and tracking companies are transforming the web into a platform where your user data is brokered and exchanged freely without your consent or even knowledge - and there is a true absence of limits to the methods trackers are willing to use to get that data from you.  Luckily, there is hope.  The Electronic Frontier Foundation (EFF) has been developing technologies that let you know exactly how much of this data you are giving out as you browse, as well as releasing tools to help you protect yourselves against the trackers.  Panopticlick and Privacy Badger help you keep your personal data private - and this talk will show you how.

  9. (2016)  The Panama Papers and the Law Firm Behind It  - Alexander Urbelis
    • The Panama Papers are beyond question one of the most significant acts of whistleblowing next to the Snowden revelations.  Yet, the full measure of what has been leaked remains to be disclosed to the public, raising considerable questions about what happened, who is implicated, and the legal and illegal acts of Mossack Fonseca, the law firm behind the breach.  This talk will review what the Panama Papers leak is, introduce the breached law firm, examine Mossack Fonseca's explanation of the breach, deconstruct and debunk their explanation, present MF systems that were more likely the cause of the breach, present alternative and more plausible theories of the breach, examine MF communications that indicate questionable and possibly illegal activity within and without the United States, step through the legal implications of MF's activities, identify the right Infosec questions clients should be asking of law firms, and provide a question and answer session to ruminate about the breach and its source.

  10. (2016)  2016 Car Hacking Tools  - Craig Smith, Eric Evenchick
    • This presentation will focus on some of the most recent car hacker tools and techniques.  You will learn how to quickly get set up to do car hacks, both professionally and in your garage.  After the demos, Craig and Eric will open up for a full-on Ask Me Anything (AMA) style panel discussion where you are free to ask any car hacking related questions you feel like.

  11. (2016)  Accessibility: A Creative Solution to Living without Sight  - Shaf Patel
    • In this presentation, Shaf will be discussing the various methods blind and visually impaired people use to accomplish everyday tasks, with an emphasis on technology, screen reading software, and application design from a blind person's perspective.  There will be live demos of screen reading software, OCR apps for smartphones, wearable devices, and mobility aids (time permitting).  There will also be a discussion on myths and stigmas relating to blindness, an audience Q&A regarding accommodating those with a visual impairment, and tips and tricks for those who develop applications to include accessibility in their core design.

  12. (2016)  All Ages: How to Build a Movement   - Deb Nicholson, Molly de Blanc
    • We want the free software movement to keep growing and one facet of successful movement building is embracing a multi-generational community.  The good news is that there is no age requirement for using, promoting, and contributing to free software.  The bad news is that we aren't always doing a great job of facilitating a diverse, inter-generational movement.  We'll take a look at what we're currently doing to bring in young people, how we are treating older people in our communities, and where there is room for improvement.

  13. (2016)  Anti-Forensics AF  - int0x80 (of Dual Core)
    • This presentation is the screaming goat anti-forensics version of those "Stupid Pet Tricks" segments on late night U.S. talk shows.  Nothing groundbreaking here, but we'll cover new and trolly techniques that forensic investigators haven't considered or encountered.  Intended targets cover a variety of OS platforms.

  14. (2016)  Ask the EFF: The Year in Digital Civil Liberties   - Kurt Opsahl, Jacob Hoffman-Andrews, Vivian Brown, Parker Higgins
    • Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation's premiere digital civil liberties group fighting for freedom and privacy in the computer age.  This session will include updates on current EFF issues such as surveillance online, encryption (and backdoors), and fighting efforts to use intellectual property claims to shut down free speech and halt innovation.  The panel will also include a discussion on their technology project to protect privacy and speech online, updates on cases and legislation affecting security research, and much more.  Half the session will be given over to question-and-answer, so it's your chance to ask EFF questions about the law and technology issues that are important to you.

  15. (2016)  Attacking the Source: Surreptitious Software Features (and How to Become Extremely Paranoid)   - Joshua
    • Forget about network perimeters - an organization's real attack surface is made up of which codebases can be interacted with or altered.  This talk explores the past history and the methods available for maliciously altering codebases and it even includes how an attacker can bring their code into your organization without even touching your perimeter.  Topics covered include everything from conceptualizing an attack path to the execution of it; including obtaining relevant target information, exploiting the human element, writing plausibly deniable vulnerable source code, and backdooring binaries.

  16. (2016)  Biology for Hackers and Hacking for Biology  - Kevin Chen, Jameson Dungan
    • Biotechnology is information technology - software that you can code and engineer.  It is becoming very clear that biology needs to be approached with the same hacker ethic and mentality as software and hardware.  Furthermore, the technology needed to hack biology is becoming much more accessible.  In this panel, you'll learn some of the basics of biology using terms and analogies that would be useful for hackers and for people in information technology.  Basic points will be outlined on how to get started in biohacking, both virtually and physically.  This talk will also cover the current state of biotechnology and how biology can be approached and improved upon through the philosophy and culture of hacking.

  17. (2016)  The Black Holes in Our Surveillance Map  - Marcy Wheeler
    • While Edward Snowden has revealed a lot about the NSA's surveillance, our federal and local governments conduct a great deal of surveillance we still don't know about.  We can begin to identify what that surveillance is by identifying the empty spaces - in criminal cases, in legislation, or timelines - where such surveillance must be.  This talk will attempt to point to some of the black holes in our surveillance map, both ones we know exist and the places where one must exist.  That's the first step in working collaboratively to expose that surveillance.  More importantly, this talk will focus on how to see these black holes, and how people around the country can work together to make them visible again.

  18. (2016)  Bringing Down the Great Cryptowall   - Weston Hecker
    • Ransomware has been running rampant for the past six years and there has been very little done to stop infections aside from deprecated signature scans and classic malware scanners.  This talk will unveil some proof of concepts that work on even the most current versions of the ransomware plaguing the networks of today, from a hacked USB device to a form of backup to making your physical machine look like a virtual machine which the malware ignores.

  19. (2016)  Bring the Noise: Ten Years of Obfuscation as Counter-Surveillance  - Daniel C. Howe
    • It has been a decade now since the release of TrackMeNot, the first privacy tool to leverage obfuscation for counter-surveillance.  In the interim, obfuscation has been actively developed, with new tools exploring its use for email (ScareMail), location-tracking (CacheCloak), advertising (AdNauseam), DNA analysis (Invisible), and beyond.  This talk reviews the development of the strategy and considers some of the questions it raises for the tool-making community.  Daniel will debut AdNauseam 2.0, the first cross-platform production release of AdNauseam, which aims at nothing less than ending advertising-based surveillance asi we know it.  Obfuscation can be defined as the strategy of using noise to hide one's true interests and/or confuse an adversary.  As obfuscation is relatively flexible in its use, it holds unique promise as a strategy for DIY privacy and security.  TrackMeNot was the first privacy tool to leverage obfuscation online, protecting web searchers from search engine profiling by hiding their queries in a cloud of generated noise.  AdNauseam directs similar techniques at the advertising networks that track users across the web, polluting user profiles and subverting the economic system that drives this pervasive form of surveillance.

  20. (2016)  Building Your Own Tor-centric ISP for Fun and (non)Profit  - Gareth Llewellyn
    • Following the Snowden revelations and with the U.K. government's revival of the Snooper's Charter legislation, Gareth was one of many people who accepted the EFF Tor challenge.  Unfortunately, many U.K. ISPs' colocation providers do not appreciate Tor exits and, after several abruptly terminated servers, he decided to build his own privacy centric, non-profit ISP so he could operate Tor exits and offer UNIX shells, etc. on his own terms.  This talk explores the process of becoming a local Internet registry in Europe, dealing with RIR polices such as IPv4 exhaustion, Tor abuse complaints, and the deployment of a broadband product that only has a Tor bridge instead of a next hop at the end of a DSL connection.

  21. (2016)  Can We Sue Ourselves Secure?  The Legal System's Role in Protecting Us in the Era of Mass Data Leaks and Internet of Things   - Alex Muentz
    • Large data breach stories just merge into one another.  Weak IoT security is no secret.   Yet the marketplace isn't fixing this problem.  Can the legal system play a part?  This talk will discuss current approaches under U.S. regulatory, product liability, and tort law to encourage vendors to secure their devices and services.

  22. (2016)  CAPTCHAs - Building and Breaking  - dr_dave, r3dfish
    • CAPTCHAs are the most common form of web activity security and they play an important role in regulating online activity.  CAPTCHAs keep bots and "blackhats" from abusing online resources by proving a user's humanity via solving a challenge that consists of a hard AI problem.  CAPTCHA development is a constantly evolving arms race with new styles and designs being created by site administrators and broken by attackers every day.  In order to keep the world wide web usable, site administrators must constantly work on developing new methods and improving CAPTCHAs to prevent automated abuse.  This talk will cover the basics of what CAPTCHAs are, what type of security they provide, the major types of CAPTCHAs, and how to attack them.  The speakers will also discuss criteria used when designing their CAPTCHA framework and cover some academic literature that is relevant to the field.  They will look at popular tools and services currently used to attack CAPTCHAs and provide some insight into the current state of bot identification.  A fresh new CAPTCHA design will be presented that uses human emotion recognition as the "hard AI" challenge.  Speakers will demonstrate how they have achieved their desired usability, scalability, and robustness levels via a real world implementation.  An overview of the tools and tool chain used (MS Emotion API, GIMP, Google APIs, Python, Django) to create the CAPTCHA challenges will be detailed.  The session will conclude with a user study and provide an analysis of the results with a discussion about some of the limitations of the project.

  23. (2016)  Censorship- and Coercion-Resistant Network Architectures   - Ed Platt
    • Decentralized network architectures can protect against vulnerabilities not addressed by strong encryption.  Encryption works well, but only when private keys can be kept secret and ciphertext can get to its destination intact.  Encrypted messages can be surveilled by acquiring private keys (FBI and Lavabit/Apple), man-in-the-middle attacks (NSA QUANTUM), or censored by blocking communication entirely (Pakistan and YouTube).  These attacks are difficult to protect against because they are social rather than technological.  But they all have one thing in common: they require centralization.  Censorship and man-in-the-middle attacks target communication bottlenecks and legal coercion targets a small number of legal entities.  This talk will discuss decentralized approaches to attack tolerance, including ongoing original research.

  24. (2016)  Censorship, Social Media, and the Presidential Election   - Elissa Shevinsky
    • There is increasing interest in the ability of companies like Facebook and Twitter to influence elections.  What are the roles and responsibilities of these companies to be fair and impartial?  Newspapers express bias and endorse candidates.  Facebook employees have even asked if they have a responsibility to (try to) prevent Donald Trump from becoming elected.  Twitter has been accused of censoring tweets supporting Donald Trump, while also allegedly censoring posts that were unfavorable to Hillary Clinton.  While that is certainly legal, is it acceptable to us as citizens?  If not, what can we do about it?  And what makes our expectations of bias from Twitter different from our expectations of The New York Times or The Daily News?  This talk is an exploration of the ways that social media can influence elections, and what that means for us as citizens.

  25. (2016)  Chinese Mechanical Locks - Insight into a Hidden World of Locks  - Lucas Zhao (UrbanHawk)
    • Chinese-made locks have traditionally had poor reputations.  The Chinese-made locks that we usually encounter in our day-to-day lives always seem to be low quality, cheap, and insecure at best, so it may seem that this is all that the Chinese make.  However, there is a whole other world of lock designs that are sold exclusively to the Chinese domestic market.  In this presentation, a variety of different Chinese lock designs will be discussed, from the prominent and innovative, such as the Yuema free spinning cylinder line of locks to the relatively obscure, such as the Chinese take on the Corbin Emhart rotating pin design.  This talk will cover the defeats of these locks, both theoretical and practical, in addition to the steps Chinese lock companies have taken to address these vulnerabilities, as well as the reasons behind the constant innovation.

  26. (2016)  The Code Archive  - Filippo Valsorda, Salman Aljammaz
    • Archiving web pages is hard.  Crawling, images, assets... JavaScript!  But archiving code is not.  It comes as content-addressed objects neatly packaged in repositories and tagged with refs.  It compresses well.  Changes can be detected in real time with the GitHub Firehose API.  Nevertheless, we need to do it today while the host is healthy, and not wait for it to start bundling adware or slowly fade away.  Otherwise, in ten years we'll find ourselves running unreproducible binaries on JavaScript emulators, or unable to build the software that could recover all our pictures because that one dependency is missing.  This is a talk about building The Code Archive, a Wayback Machine for git.  Every time a repository changes on GitHub, Code Archive systems fetch it and archive all the files, commits, tags, and branches as they were at that time.  Then you can clone a repository as it was at any point in time, even if the original has been rebased, has disappeared, or GitHub is down.  There's a lot of fun to be had when (ab)using the git protocol to clone and pull millions of repositories to the same database.  Speakers will show what git looks like on the wire and how fetches are optimized.  Also, all the Go code powering the Archive is available... on GitHub.

  27. (2016)  Code is from Mars, the Courts Are from Venus: Reverse Engineering Legal Developments on Reverse Engineering  - Sebastian Holst, Alexander Urbelis
    • This past May, in response to the growing sophistication of cyberattacks and application exploits, U.S. lawmakers (almost unanimously) passed the first-ever federal law concerning trade secret protection: the Defense of Trade Secrets Act.  Under the DTSA, however, reverse engineering is protected and deemed 100 percent legal.  Within weeks, the EU followed with their own directive increasing trade secret protection while protecting reverse engineering.  This talk discusses how this new law impacts reverse engineering, the pros and cons of tying reverse engineering to the courts, best practices for code development, limitations on reverse engineering, counterattacks to those limitations, and counterattacks to the counterattacks.

  28. (2016)  Coding by Voice with Open-Source Speech Recognition  - David Williams-King
    • Carpal tunnel and repetitive strain injuries can prevent programmers from typing for months at a time.  Fortunately, it is possible to replace the keyboard with speech recognition - David writes Linux systems code by voice.  The key is to develop a voice grammar customized for programming.  A community has evolved around hacking the commercial Dragon NaturallySpeaking to use custom grammars, but this method suffers from fragmentation, a steep learning curve, and frustrating installation difficulties.  In an attempt to make voice coding more accessible, David created a new speech recognition system called Silvius, built on open-source software with free speech models.  It can run on cloud servers for ease of setup, or locally for the best latency.  He and his collaborators have also prototyped a hardware dongle which types Silvius keystrokes using a fake USB keyboard, and requires no software installation.  This talk will include live voice-coding demos with both Dragon and Silvius.  The hope is that Silvius will lower the bar for experimentation and innovation, and encourage ordinary programmers to try voice coding, instead of waiting until a crippling injury throws them in at the deep end.
    • Slides

  29. (2016)  Come into My (Biohacking) Lab and See What's on the Slab  - Tom Keenan
    • It's 1979 and bright young hackers are torturing their Commodore PETs and Apple IIs to make all the pagers beep on a university campus, or take control of a dam in Alberta.  (Both are true stories - Tom was there.)  Fast-forward to 2019 and their children (or grandchildren) are doing the same thing - driven by our universal desire to make technology "do things it's not supposed to be able to do."  Except now, the role of personal computers is being played by CRISPR Cas9 gene editing gear that they bought for a few dollars on eBay.  What can they do with it?  Make animals glow in the dark?  Destroy all life on this planet?  Hold us hostage with bio-ransomware?  This talk will examine the fast moving science behind biohacking and how it will change our lives.  It will also apply the "technocreep framework" to predict which aspects of biohacking will be considered cool and which will seem creepy, even to the freethinking folks who attend HOPE.  As a bonus, you'll learn what happens when you put sponges and electrodes on your head and run direct current through your brain.

  30. (2016)  Computer Science Curricula's Failure - What Can We Do Now?  - Ming Chow, Roy Wattanasin
    • We are still facing the same security vulnerabilities from over a decade ago.  The problems are not going away anytime soon and a reason is because computer science curricula are still churning out students who are not even exposed to security.  This talk will address the lack of emphasis on information security in computer science curricula, how CS curricula have an obligation, how to gradually fix the problem by integrating security into many computer science undergraduate and graduate classes, and success stories from students.  This talk will also discuss what Tufts and Brandeis are currently working on to further address the security education problem by creating a joint cyber security and policy program that spans multiple departments.  Additional points and feedback from the audience are encouraged to help with the issue.

  31. (2016)  Constructing Exocortices with Huginn and Halo  - The Doctor
    • Huginn is an open-source human capability-amplifying and augmentation system which implements scenarios - networks of autonomous software agents that collectively analyze data and use it to accomplish sophisticated tasks on behalf of its users.  External to Huginn is the Halo, a collection of software constructs optimized for carrying out tasks too complex for Huginn due to resource requirements, contention, or reliance upon lower level libraries, including synthesizing speech, placing Voice over IP calls, and carrying out limited secretarial duties to facilitate human interaction.  The development histories of both Huginn and Halo will be discussed during the first part of the talk with representative examples of the presenter's agent networks to demonstrate the architecture of scenarios as well as solutions to practical problems.  Agents, the basic building blocks of Huginn scenarios and the software constructs of Halo will be briefly detailed to give an overview of some of possibilities of the two interrelated software systems.  The talk will conclude with brief descriptions of some of the tasks that HOPE attendees can accomplish through the use of both Huginn and Halo.

  32. (2016)  Crypto War II: Updates from the Trenches  - Matt Blaze, Sandy Clark
    • For several years, law enforcement has been complaining that legal wiretaps are "going dark" (especially when encryption is used), and has been lobbying lawmakers to mandate "surveillance-friendly" technology that allows the government to break encryption and unlock devices under certain circumstances.  At the same time, computer and network security is universally recognized to be in an increasingly dangerous state of peril, and technologists worry that "backdoor" mandates will only make things worse.  We've been here before, not long ago.  In the 1990s, after the government proposed the "Clipper Chip" key escrow system, we had a similar debate with similar stakes.  It was finally resolved when the government essentially gave up and finally allowed cryptography to proliferate.  This talk will review the current cryptography debate, will examine the risks of the "keys under doormats" that the FBI is asking for, and will explore technical alternatives that could satisfy the needs of law enforcement without making computer security more of a mess than it already is.  In particular, Matt and Sandy will examine the viability, and risks, of law enforcement exploitation of existing vulnerabilities in targets' devices to obtain wiretap evidence.

  33. (2016)  De-Anonymizing Bitcoin One Transaction at a Time  - David Décary-Hétu, Mathieu Lavoie
    • Bitcoin is an established virtual currency well known for enabling affordable and efficient transfers of money between individuals and entities.  With its market cap of over $7 billion and hundreds of thousands per day, the Bitcoin currency has become popular enough for offenders to be able to hide among its users when they purchase illicit goods and services online or need to receive extortion payments.  The aims of this presentation are twofold.  The first is to present an open-source tool developed by the panelists that analyzes all of the Bitcoin transactions and regroups Bitcoin addresses based on their incoming and outgoing transactions.  This allows for a more accurate mapping of individuals' online activities no matter how many Bitcoin addresses they are using.  The tool, as well as a database of all nodes identified by the tool, will be released on the day of the conference.  The second aim of this presentation is to provide real world use cases for the tool to better understand online illicit activities.  To do so, David and Mathieu will present two case studies that will follow the evolution through time of the revenues generated by online illicit groups and the strategies they used to manage the incoming bitcoins.  This talk will be of interest to attendees looking to better understand how the Bitcoin currency works and the attacks that can be used to de-anonymize Bitcoin users.  A live demonstration will explain how the open-source tool works and the strategies that could be used to preserve one's anonymity in the Bitcoin network.

  34. (2016)  Deconstructing Ad Networks for Fun and Profit  - Timothy Libert
    • This talk focuses on an open-source software tool, webXray, which detects the presence of third-party data flows on the web and attributes such flows to the corporations which receive user data.  The talk will first describe the challenges, dead ends, and solutions encountered in developing the software so that developers and novices in the audience may understand the nature of the problem domain.  Second, the talk will cover how to use the tool to analyze targeted populations of web pages with an emphasis on scaling and cost considerations.  Third, the talk will describe findings in three areas: tracking found on medical websites, Chinese websites, and newspaper websites including measures of user exposure to malware-hosting domains embedded in ostensibly trusted websites.  The talk will conclude with a theoretical discussion of how those seeking to leverage ad networks to deliver malware may pick the best networks suited to their objectives.

  35. (2016)  Democratizing Wireless Networks with LimeSDR: Open-Source, Field-Programmable RF Technology  - Ebrahim Bushehri
    • This talk presents new, low-cost, open-source, field programmable RF technology, where flexibility is extended from the digital to the RF domain.  See demonstrations from the open-source community using the LimeSDR platform, which incorporates two transmitters and two receivers covering 100 kHz to 3.8 GHz which can emulate GSM, LTE, UMTS, Wi-Fi, Bluetooth, Zigbee , RFID, HDTV, radio astronomy, passive radar, 2G/3G/4G cellsites, IoT gateway, amateur radio, wireless keyboard/mouse transmission/detection, aviation transponders, utility meters, satellite reception, remote tire pressure monitoring, drone command and control, RF test and measurement, and more.

  36. (2016)  Detour Through Their Minds: How Everyday People Think the Internet Works  - Gillian "Gus" Andrews
    • When you work in IT or infosec, it may feel like you're constantly fighting a battle to bring the non-technical people you work with up to speed on how technologies work.  When you help family members with their computer problems, you may just want to throw up your hands and scream "It's no use!  They just don't get it!"  But when you dig a little deeper, as a number of studies have done, you find that the average person does have some knowledge about how the Internet works.  They build on this knowledge every day - but sometimes they're incorporating what they've learned from that scene on NCIS where two people are using a keyboard at once.  They may hold some common misconceptions.  Or they may be sooo close and just need one little additional piece of information.  Gus will share insights from the study she has been working on for the past year about average people's mental models of the Internet, along with a number of other studies from human-computer interaction and security research.  Key concepts like "mental models," "fragile knowledge," "stereotype threat," and "learned helplessness" will be explored.  In addition, ways the gaps in people's knowledge impact digital security and how we might strategize on a large scale to help fill those gaps will be explored.  You'll come away with better strategies for helping empower the non-technical folks in your life to solve their own problems.

  37. (2016)  FOIA and Public Records Hacking: How to Complete a FOIA Request or Dox Yourself via the Privacy Act  - Caitlin Kelly Henry
    • Learn how the key to writing successful FOIA requests is reverse engineering agency data structures.  This talk will include an overview on writing successful FOIA or Privacy Act requests, including updates from recent cases.  You will learn the step by step process of drafting a request, using the FBI as an example.  This talk is great for activists, students, researchers, journalists, and people with security clearances (especially after the OPM hack).

  38. (2016)  FOIA at Fifty  - Jameel Jaffer, David Pozen
    • The Supreme Court has stated that the Freedom of Information Act "defines a structural necessity in a real democracy."  On the 50th anniversary of its enactment, now is an opportune moment to reflect on the role FOIA has played in our legal and political system.  This conversation will bring together Jameel Jaffer from the ACLU and David Pozen from Columbia Law School to consider the past, present, and future of FOIA.  They will discuss virtues and drawbacks of the FOIA model, FOIA's relationship with technology and other transparency mechanisms, the effectiveness (or ineffectiveness) of FOIA in the national security context in particular, and lessons to learn from foreign and state-level approaches to regulating government openness.

  39. (2016)  Freedom and Privacy in Our Lives, Our Governments, and Our Schools  - Richard Stallman
    • If we don't control the program, it controls us.  It is clearer every year that nonfree programs, beyond the basic injustice of giving the developer or owner unjust power over the users, also tends to be malware, for instance designed to restrict users or snoop on them.  Since government agencies and schools require people to run software to exercise their rights, this software must all be free, but increasingly they impose use of nonfree software and commercial snooping services.  We must now organize to demand that they stop.

  40. (2016)  F*ck it, We'll Do It Live: Eight Years of Radio Statler!  - Beaches, Nikgod, TechDarko, Bunni3burn, Johnny Xmas, Stoppay, XioNYC
    • Since 2008, Radio Statler! has been broadcasting original content from HOPE to the rest of the world: interviews with speakers, extended Q&As, panels, and the occasional glimpse into everything that happens outside the talk rooms.  The panel will take you through how and why Radio Statler! started, the obstacles faced running a temporary radio studio, and some of the war stories of the things that have gone terribly, terribly wrong along the way.

  41. (2016)  Go Hack Yourself!  - Michael Hernandez
    • Hacking of all kinds requires discipline and concentration.  Over the past few years, Michael has been seriously practicing yoga and meditation and has found that it's been a great help in many areas of his life, including his work as a hacker and programmer.  Eating healthy and exercising your mind and body sounds like a load of crap to a lot of hackers but the reality is that if you want to have a long sustained life that you can continue to use for hacking and exploration, you'll want to keep your mind and body healthy.  Practicing concentration daily and learning to meditate can help you literally hack your mind, and help you make changes within yourself you might have thought impossible.  Practicing discipline in these areas will also bring confidence and inner strength that will help you in whatever kind of hacking you're doing or planning to do.

  42. (2016)  Hackers Are Whistleblowers Too: Practical Solidarity with the Courage Foundation  - Nathan Fuller, Grace North, Naomi Colvin, Carey Shenkman, Lauri Love, Yan Zhu
    • In the two years since the Courage Foundation was launched, they have supported beneficiaries at every stage of the information exposure process: hacktivists, investigative journalists, and human rights defenders.  Most recently, the Courage Foundation announced their campaign to raise European funds and awareness for Chelsea Manning.  They believe the blurred line between activists and journalists needs to be embraced as a spectrum of solidarity; each of these actors needs the others to bring information to public attention, and so each deserve our support.  While whistleblowers like Edward Snowden enjoy international appreciation, hackers are often marginalized as outsiders who don't enact real change.  But it's high time we recognized their value, understanding that - since the information war occurs largely online - digital activists are those that governments seek to make the biggest examples of.  In this session, the speakers will provide updates on their ongoing cases, including Barrett Brown's and Chelsea Manning's, discuss some of the systemic issues encountered along the way, and then solicit your input.  This is a two-way conversation.  The purpose is to bring the kind of support Edward Snowden gets to all beneficiaries - and your ideas of how to get there are welcomed at this panel discussion.  Naomi Colvin and Nathan Fuller from the Courage Foundation will recap what we've learned in the past two years and what they plan to do going forward.  Grace North prison-rights activist heading the Jeremy Hammond support network, who has also worked closely with Lauri Love on his case, will discuss the challenges Jeremy continues to face and what we need to do for Lauri to prevent him finding himself in the same situation.  Lauri will be joining the discussion by video feed to talk about his ongoing battle against extradition to the United States.  Yan Zhu, security software engineer and friend of Chelsea Manning, will talk about how we can help Chelsea from the outside.  Carey Shenkman, First Amendment and human rights attorney with the Center for Constitutional Rights representing journalists including Julian Assange and WikiLeaks, will explain the need for a public interest defense for journalistic sources.

  43. (2016)  Hackers Got Talent  -
    • Do you have a cool hack?  This is your chance to share it with a whole bunch of other hackers.  Hacks will be judged by a combination of panelists and audience.  First place wins a valuable prize!

  44. (2016)  Hacking DNA: Heritage and Health Care  - Nina Alli
    • Humans are the compilation of bio-code that has been changing and evolving for almost 200,000 years.  In some ways, we are the oldest open-source project around, but not on GitHub - yet.  In years past, DNA sequencing and analysis was available only to a handful of scientists with huge labs and nearly unlimited budgets.  Now that world is changing.  There are products and services available today that bring individual DNA sequencing to your fingertips, and digging into your own source code has never been easier or cheaper.  Analyzing DNA can not only reveal secret ancestries, but can provide a level of insight and history into your health that doctors in the past have only dreamed of.  This talk will discuss how and why you can perform your own genetic background check, and what it means for your past, present, and future.

  45. (2016)  Hacking Housing  - Luke Iseman, Heather Stewart
    • Luke and Heather will discuss their work building shipping container based, off-grid, open-source houses and factories.  They will provide a crash course in getting and converting containers, including specific recommendations on how to modify them into solar-powered, comfortable living and working spaces.  This is relevant because it's silly for us to live and work in corporate-owned environments built by somebody else, rather than hacking our own sustainable, affordable alternatives.

  46. (2016)  Hacking Machine Learning Algorithms   - Kyle Polich
    • Algorithms control more and more of the systems we interact with on a daily basis.  Critical decisions are executing without direct oversight by machine learning models.  These systems, like any system, should be continuously taken apart and inspected to see how they work.  Examining a machine learning model is not as easy as examining source code.  This talk goes into detail on how to hack machine learning models and similar systems.  Could an algorithm be racist?  How can we detect it?  Live examples in Python will be demoed and available on GitHub, and only basic programming knowledge is required to understand the talk and reproduce the examples.

  47. (2016)  Hacking Sex: Toys, Tools, and Tips for Empowerment and Pleasure   - Kit Stubbs
    • Hacker culture celebrates technological empowerment: encouraging people to move beyond passive consumerism towards building and modifying technology to better meet their own needs.  Hacking sex means expanding our definition of "sex;" recognizing that no two of us have the exact same biology, (a)sexuality, or desires; and building and modifying toys and equipment to enhance our own pleasure.  Join Kit "where did this b!tch get [their] doctorate" Stubbs for a look at technological empowerment for sexuality and pleasure.  Recent developments in sex/tech will be covered, including crowdfunded sex toys, a patent troll, open-source sex toys, and 3D printing, with plenty of resources for folks new to sex/kink-positive DIY.

  48. (2016)  Hacking through Business: Theory and Logistics   - Mitch Altman, Limor Fried, Phil Torrone, Ben Dubin-Thaler
    • It's rare that you see an engineer as CEO, but occasionally taking a technical idea to its logical conclusion requires the person who knows what's going on inside the black box to take the reigns.  Someone who knew everything they needed to know to start the project technologically is suddenly confronted with human problems and legal issues and paths forward that might require new types of specialized knowledge and very different gut decisions.  This extended panel discussion will address both the blue sky possibilities of a company led by tech, as well as the plethora of challenges thrown at anyone who finds it necessary to not let someone else run their business.

  49. (2016)  How Anonymous Narrowly Evaded Being Framed as Cyberterrorists   - Gabriella "Biella" Colema
    • Over the years, Biella has used many different words and phrases to describe Anonymous: hydra, trickster, confusing, enchanting, controversial, frustrating, unpredictable, stupid, and really stupid.  But rarely has she ever argued seriously against the idea that Anonymous is tantamount to cyberterrorism.  How did Anonymous avoid the title of cyberterrorists when they were perfectly positioned to earn it?  Biella will discuss the reasons such as the adoption of the Guy Fawkes mask, the timing of their most important operations, and the role of pop cultural representations of hackers like Mr. Robot that allowed them to narrowly escape this designation.

  50. (2016)  How to Torrent a Pharmaceutical Drug   - Michael Swan Laufer
    • Why are people still being left to die from treatable diseases when they can't afford the arbitrarily inflated prices of patent-protected medications?  As hackers, we believe that when the infrastructure fails, we must have a way to fall back to DIY methods.  Medicine should not be an exception to this.  Pharmaceuticals are just chemicals, chemicals are made using chemistry, and chemistry can be automated.  Come learn how anyone can make patent-protected medications at home using a new open- source automated chemical reaction chamber made from off-the-shelf parts.  One no longer has to have a science background to do chemistry.  We can save our own lives.  Speakers will detail how the mechanism can be built, how it is programmed, and distribute the plans and programs live at the talk.  The programs for drug synthesis and the design of the mechanism can be shared over any digital channel - and can be improved and modified by any end user.  A highly controversial drug will be synthesized live on stage during the talk.

  51. (2016)  I "Hacked" for China   - Zimmer Barnes
    • For six months, Zimmer was hacker-in-residence for a top Chinese engineering university, tasked with mentoring students and building projects.  He encountered brilliant Chinese hackers and incredible startups and built several projects aimed at reducing air pollution in Beijing.  After his residency, he stayed in Beijing for four months and helped to cofound Q Space, Beijing's first feminist makerspace which now holds regular workshops and events, and has over 300 members in their group chat.  If you've ever wanted to travel to China as a hacker, Zimmer will be happy to share everything he wishes he knew before he went.

  52. (2016)  Information Overload and the "Last Foot" Problem   - Nick Lum, Andrew Cantino
    • There's so much to read and so little time.  Unlike past generations who awoke to find a single newspaper on their doorstep, we open our smartphones and computers to find thousands of newspapers, websites, and blogs beckoning our attention.  With this deluge of reading material, we're left with a "last foot" problem: how do we get all this information from our screens into our brains?  This talk will give a brief history of the written word, describe neurological aspects of the reading process, and explore some of the new innovations that aim to let us read more quickly and efficiently on-screen.

  53. (2016)  The Internet Society   - Joly MacFie
    • The Internet Society is an international, non-profit organization founded in 1992 to provide leadership in Internet-related standards, education, access, and policy.  Its mission is to promote the open development, evolution, and use of the Internet for the benefit of all people throughout the world.  Their efforts and skills are directly responsible for the streaming and archiving of The Eleventh HOPE, so please help support their efforts and consider starting a chapter in your community.

  54. (2016)  Iridium Satellite Hacking   - Stefan "Sec" Zehl, schneider
    • The Iridium satellite system has been in orbit for over 15 years now and provides various data and voice services.  This talk will show how to use Software Defined Radio (SDR) to receive and decode data from the Iridium satellite network and how a lot of reverse engineering was performed to understand the protocol and decode the details.

  55. (2016)  Is the Brain the Next Hackable Driver?   - Ellen Pearlman
    • Do our EEG, fMRI, and other biometric data contain the essence of who we are and what we think?  In the future, could this data be used as an identifier for security and thought modification as well as exploring virtual worlds?  If our "brainotypes" or "brain fingerprints" and concurrent cognitive processes are monitored, how do we prepare for this looming horizon?  Though no one is entirely sure, these questions invite both scientific and metaphorical approaches addressing these issues.  Ellen will discuss the emergence of technologies, research, and methods on brain datatyping; privacy and its ethical implications; sending and receiving motor commands between two different brains; moving robotic prosthesis through thoughts; the formation of memory; manipulating memory via frequencies of light; and hacking Brain-Computer Interfaces (BCIs) to extract vital information.  Keeping these methods and techniques in mind, she will also show a brief excerpt from her own creation "Noor - a Brain Opera" which asks the question "Is there a place in human consciousness where surveillance cannot go?"

  56. (2016)  Keynote Address - Cory Doctorow   - Cory Doctorow
    • We are so stoked to have Cory Doctorow as our keynote this year.  We've been trying to get the stars to align for many HOPEs, and this time they did.  But we're glad we waited until now, since so much has happened in the past few years that Cory has been on top of - Snowden, Manning, privacy, copyright issues, surveillance - and his talk will no doubt open your eyes even more.  As co-editor of Boing Boing, special advisor to the Electronic Frontier Foundation, a prolific writer of both fiction and non-fiction, and a vocal proponent of changing our copyright laws, Cory really has a lot of super-important and relevant thoughts to share with our HOPE audience.

  57. (2016)  Leak Hypocrisy: A Conversation on Whistleblowers, Sources, and the Label "Espionage"   - Jesselyn Radack, Carey Shenkman, Naomi Colvin
    • The two-tiered injustice system: high-level officials who leak for political gain get cover; those blowing the whistle on crimes and abuse face decades in prison.  The problem is urgent, costing daily the liberty of Edward Snowden, Chelsea Manning, and many whistleblowers, as well as the liberty of Julian Assange, a publisher.  In this critical moment, join two leading lawyers and the Courage Foundation for a conversation on attacks on freedom of expression, the failure of internal oversight mechanisms, the serious need for a "public interest" defense for truth tellers, and the promise of a growing international movement to promote and protect them.

  58. (2016)  LinkNYC Spy Stations   - Benjamin Dean, Mariko Hirose
    • A report on the new LinkNYC kiosks' origins, legislation, design, manufacture, installation, and operation, along with the civil liberties threat they pose and options we can implement to inhibit and avoid their spying capabilities.

  59. (2016)  Lockpicking in Real Life versus on the Screen   - Nite 0wl, Max Power, Deviant Ollam, Babak Javadi, and many others from TOOOL and LockSport International
    • We all know that Hollywood has a difficult time portraying hackers accurately.  This quirk often extends to the realm of showing lockpicking in movies and on TV.  But sometimes, a film gets it really right!  This talk is both an introduction to lockpicking (in case you still need to learn) as well as a walk through some of the best - and some of the worst - scenes of lockpicking that have ever been seen by movie and TV audiences.  Learn about how to be a better lockpicker and a better filmmaker... all at the same time!

  60. (2016)  LockSport Roadshow: Bring Your Oddities!   - TOOOL and Friends
    • There have been plenty of talks at HOPE teaching you to pick conventional locks.  But what about non-conventional locks?  This panel - which will require much audience participation - is all about unique and interesting locks.  Have a weird lock or even a strange key and want to know more about it?  Bring it to the stage!  If you can stump our esteemed panel, you'll win a prize!  Don't be shy... bring out your unique and strange lock hardware and, if you're really brave, give the panel a chance to try to pick it!

  61. (2016)  Matehacking: Legalizing Autonomous Production and Permaculture - Establishing a Hack Farm   - Fabrício do Canto
    • This talk will focus on a proposal to create a "mate hacking farm."  Technologization is running full power in the direction of monoculture and industrial mass scale drying of mate using eucalyptus burning as an energy source.  This will bring dramatic ethnological and environmental impact to the South American Pampas.  Hackers can play an important role by developing easy to construct, recycled, upcycled, and DIY technology for the decentralized production of yerba mate in both traditional and new ways.  This draws attention to the need for a solution for food sovereignty in the southern hemisphere.  The "mate hacking farm" would be a fantastic place to tunnel in, get wired, and push new technologies and open-source forest management solutions.  Any activistic, fantastical, solidary and commerce-free ideas and concepts are welcome to be executed there and planned for now.

  62. (2016)  Medical Devices: Pwnage and Honeypots   - Scott Erven, Adam Brand
    • We know medical devices are exposed to the Internet both directly and indirectly, so just how hard is it to take it to the next step in an attack and gain remote administrative access to these critical life saving devices?  This talk will discuss over 30 CVEs Scott has reported over the last few years that will demonstrate how an attacker can gain remote administrative access to medical devices and supporting systems.  Over 100 remote service and support credentials for medical devices will be presented.  So is an attack against medical devices a reality or just a myth?  Now that we know these devices have Internet facing exposure and are vulnerable to exploit, are they being targeted?  Scott and Adam will discuss six months of medical device honeypot research, showing the implications of these patient care devices increasing their connectivity and steps that can be taken to reduce risk associated with these life saving devices.

  63. (2016)  Mesh VPN with Service Discovery   - Spencer Krum
    • Tinc provides a secure mesh VPN for any number of hosts.  Spencer and his friends used this to build a network linking their homes, laptops, and various hosted machines.  They started doing some cool things with it such as UPnP and NFS, things that would be impossible to do securely over the public Internet.  This talk will highlight their experiences along the way.

  64. (2016)  Monitoring Dusty War Zones and Tropical Paradises - Being a Broadcast Anthropologist   - Mark Fahey
    • Tuning in distant foreign radio and television stations is a conduit to unique and exotic information.  These signals are often confronting, uncensored, and unsanitized.  In the western world, we blur or pixelate images of death and torture, but signals from war zones or rebellions show tragedies happening live on the air.  Other signals broadcast the joy of life on this planet through exotic song, music, and film.  Digital wide-band recordings of the electromagnetic spectrum allow virtual time travel, a form of mental teleportation whereby recorded spectrum is tuned to hear stations as if they were being tuned in real time.  Take a virtual tour of Mark's monitoring station in Sydney, Australia which is wired to access the world's mass media via whatever delivery conduit is needed to capture the content.  The station receives hundreds of thousands of inbound digital audio and video channels that let him monitor domestic radio and television from most parts of the world.  If he wants to watch breakfast television from Tibet, or maybe the nightly news from the remote Pacific islands of Wallis and Futuna, then it's available in perfect studio quality.  You'll also see his visits to remote broadcasters and rare, uncensored video from telejournalists that captures the tragedies and joy served up by our planet.

  65. (2016)  National Security Letters: The Checks and Balances Aren't Strong Enough - Sometimes They're Nonexistent   - Nicholas Merrill
    • Twelve years have passed since Nicholas Merrill first began his lawsuit challenging the constitutionality of the USA PATRIOT Act and, specifically, the warrantless searches known as National Security Letters (NSLs).  Now that he can tell the full story, what really happened?  How much has actually changed because of the 12-year court case?  If the government lost, why are NSLs still being issued at a rate of 50,000 per year?  Who is doing anything about this problem, and what are they doing?  What are the respective roles of litigation, legislation, and technical approaches to the issue of privacy?

  66. (2016)  The Next Billion Certificates: Let's Encrypt and Scaling the Web PKI   - Jacob Hoffman-Andrews
    • Let's Encrypt is a free and automated certificate authority to encrypt the web, launched in December 2015.  Jacob will explain why HTTPS is important to Internet freedom and the role certificate authorities play.  He'll give an introduction to the ACME protocol that Let's Encrypt uses to automate validation and issuance, discuss Let's Encrypt's progress by the numbers, and outline some of its future plans.

  67. (2016)  Now and Then, Here and There   - Jason Scott
    • In the last few years, the Internet Archive has steered deeply into the worlds of software history, hacker presentations, and artifacts from all parts of technology's past and present.  Jason Scott, the Archive's software curator and inside man, walks through both the current stacks of technology and hacker culture history and reveals in what directions the nonprofit library hopes to expand.  Lots of amusing imagery and endless lost weekends will ensue.

  68. (2016)  The Onion Report   - asn, Nima Fatemi, David Goulet, Erinn Clark
    • The Tor community, network, and ecosystem are growing and evolving at a very fast pace - from new secure applications using Tor to deploying relays in public libraries around the world.  Tor as a project, but first and foremost as a large community, is at the forefront of technical, social, economical, political, and cultural battles pertaining to anonymity and basic human rights.  This talk will cover the state of Tor on all levels: organizational, community, and technical.  Recent and upcoming software developments, movement in onion (a.k.a. hidden) services land, attacks on the network and how we are fighting back, community projects, and much more will be covered.  This is not about the Dark Web but rather about a Secure Web (copyleft pending).

  69. (2016)  Only You Can Stop Police Surveillance - Here's How   - Matt Cagle, Mariko Hirose, Jared Friend
    • As America debates policing reforms, police departments continue to rapidly acquire surveillance technology in secret, often with federal grant funds.  Whether it's Stingray cell surveillance devices or social media monitoring software, invasive tools are being deployed without democratic debate or safeguards to prevent racial profiling.  But while this war against surveillance may seem like a losing one at times, advocates are winning key battles in cities across the U.S. Join civil liberties advocates and ACLU attorneys from New York, San Francisco, and Seattle for a discussion of how to increase transparency, frame the debate, and create meaningful policy reforms that protect civil liberties and civil rights.

  70. (2016)  Open Microphone   -
    • In addition to the ongoing fourth track, we now have a way you can express yourself to the entire HOPE crowd beginning at midnight on Friday night.  It's kind of like lightning talks except with much longer lightning.  You'll have up to 15 minutes to say your piece and make your points.  (You can even sing a song if you wish - it's an open microphone, after all.   Sign up at the InfoDesk on Friday and you will be called upon in the order that you signed up.

  71. (2016)  Open-Source Malware Lab   - Robert Simmons
    • The landscape of open-source malware analysis tools improves every day.  A malware analysis lab can be thought of as a set of entry points into a tool chain.  The main entry points are a file, a URL, a network traffic capture, and a memory image.  This talk is an examination of the major open-source tools that satisfy the analysis requirements for each of these entry points.  Each tool's output can potentially feed into another tool for further analysis.  The linking of one tool to the next in a tool chain allows one to build a comprehensive automated malware analysis lab using open-source software.

  72. (2016)  Orbital Mechanics Ate My Weblog   - Edward K. Beale
    • At high latitudes, orbital mechanics make deep-ocean Internet almost impossible.  In most cases, it is not wattage, atmospheric attenuation, latency, or antenna position that are the culprits - it is geometry.  In 2001, Edward blogged about his voyage to Antarctica aboard an icebreaker as lead helicopter pilot.  Twelve years later, he completed a full shipboard circumnavigation and delivered a daily weblog to several hundred crowdsourced readers, later self-published in the book West By Sea.  Across those years, Internet access got better, but at high latitudes it still sucked.  In addition to sea stories about massaging crappy packets, this talk outlines the basics of deep ocean bandwidth in layman's terms, gives a short modern history of the tools and tech, outlines new innovations that meld terrestrial and orbital bandwidth for offshore users, and focuses on the burgeoning need for better solutions at high latitudes.

  73. (2016)  The Ownerless Library   - Paul Kernfeld
    • Managing a subversive digital library takes courage: Julian Assange is in exile and the founders of The Pirate Bay received prison sentences.  How can we design a digital library without a central administrator to attack?  To meet this challenge, we'll sneak data into the Bitcoin blockchain, permanently destroy bitcoins, and build a peer-to-peer network entirely out of browsers.  If we do it right, we won't be able to take the library down even if we wanted to!

  74. (2016)  A Penetration Tester's Guide to the Azure Cloud   - Apostolos Mastoris
    • The wide adoption and the benefits of cloud computing has led many users and enterprises to move their applications and infrastructure towards the Cloud.  However, the nature of the Cloud introduces new security challenges, therefore organizations are required to ensure that such hosted deployments do not expose them to additional risk.  Auditing cloud services has become an essential task and, in order to carry out such assessments, familiarization with certain components of the target environments is required.  This talk will provide insight into the Microsoft Azure Cloud service and present practical advice on performing security assessments on Azure-hosted deployments.  More specifically, it will demystify the main components of a cloud service and dive further into Azure-specific features.  The main security controls and configurations associated with each of the mainstream Azure components will also be explored.  Areas that will be covered include role-based security, secure networking features, perimeter security, encryption capability, auditing, and monitoring of activities within the Azure Cloud environment.  Additionally, the talk will include the demonstration of a new tool that uses the Azure PowerShell cmdlets to collect verbose information about the main components within a deployment.  The tool also provides functionality to visualize the components within a network infrastructure using an interactive representation of the topology and the associations between the deployment's components.

  75. (2016)  The Phuture of Phreaking   - The Cheshire Catalyst
    • Phone phreaking has always been about the exploration of the Public Switched Telephone Network (PSTN).  Richard Cheshire will discuss phreaking in the age of VoIP (Voice over Internet Protocol).  Downloading the Phone Loser's Blue Box app is not a prerequisite.

  76. (2016)  Presidential Twitter Bot Experience   - Roni Bandini
    • Until a few months back, Argentina had a monarchy-styled government that included huge corruption, nepotism, and political violence.  Néstor Kirchner was president for four years, then his wife, Cristina Fernández de Kirchner, was president for the following eight years.  Instead of giving press conferences, she used the official Twitter account (@CFKArgentina) to spread Goebbels-styled propaganda, send threats to the opposition, and exalt fanatics of all kinds.  This talk will explain the adaptation of an old chatter bot engine designed for a porn web site that now is used for a fake presidential Twitter account.  Day-by-day, lots of political tweets are answered by this bot and almost no one detects that a piece of code is responsible for the mise-en-scéne.
    • My President Twitter Bot Experiment

  77. (2016)  Privacy, Anonymity, and Individuality - The Final Battle Begins   - Steve Rambam
    • First came the assault on privacy.  Name, address, telephone, DOB, SSN, physical description, friends, family, likes, dislikes, habits, hobbies, beliefs, religion, sexual orientation, finances, every granular detail of a person's life, all logged, indexed, analyzed and cross-referenced.  Then came the gathering of location and communication data.  Cell phones, apps, metro cards, license plate readers and toll tags, credit card use, IP addresses and authenticated logins, tower info, router proximity,i networked "things" everywhere reporting on activity and location, astoundingly accurate facial recognition mated with analytics and "gigapixel" cameras and, worst of all, mindlessly self-contributed posts, tweets, and "check-ins," all constantly reporting a subject's location 24-7-365, to such a degree of accuracy that "predictive profiling" knows where you will likely be next Thursday afternoon.  Today we are experiencing constant efforts to shred anonymity.  Forensic linguistics, browser fingerprinting, lifestyle and behavior analysis, metadata of all types, HTML5, IPv6, and daily emerging "advances" in surveillance technologies - some seemingly science fiction but real - are combining to make constant, mobile identification and absolute loss of anonymity inevitable.  And, now, predictably, the final efforts to homogenize: the "siloing" and Balkanization of the Internet.  As Internet use becomes more and more self-restricted to a few large providers, as users increasingly never leave the single ecosystem of a Facebook or a Google, as the massive firehose of information on the Internet is "curated" and "managed" by persons who believe that they know best what news and opinions you should have available to read, see, and believe, the bias of a few will eventually determine what you believe.  What is propaganda?  What is truth?  You simply won't know.  In a tradition dating back to the first HOPE conference, for three full hours Steve Rambam will detail the latest trends in privacy invasion and will demonstrate cutting-edge anonymity-shredding surveillance technologies.  Drones will fly, a "privacy victim" will undergo digital proctology, a Q&A period will be provided, and fun will be had by all.

  78. (2016)  SecureDrop: Two Years on and Beyond   - Garrett Robinson
    • Two years ago, Freedom of the Press Foundation introduced HOPE to their just-launched SecureDrop project, the open-source whistleblower submission system for journalists and news organizations that was originally created by the late Aaron Swartz.  Now over three dozen news organizations around the world are using SecureDrop, and they've learned a ton about how journalists and sources interact securely.  This talk will share a lot of this information for the first time.  How is SecureDrop working in newsrooms?  What challenges and threats does the system face?  And what does the next generation SecureDrop look like?

  79. (2016)  The Securitization of Cyberspace and Its Impact on Human Rights   - Sacha van Geffen, Mallory Knodel, Camille Francoise
    • A handful of representatives from governments, the private sector, and civil society comprise an international working group of the Freedom Online Coalition (called "An Internet Free and Secure") that is tasked with harmonizing human rights and security.  But protected rights like privacy and free speech already are security.  Rights and security are not antithetical; they are compatible.  Government power and corporate profits fuel the rights versus security narrative that has dominated the U.S. and Europe since the introduction of the U.S. PATRIOT Act.  To dislodge this dominant narrative, this panel has developed over the course of two years a human rights respecting definition of cyber security and a normative statement of policy recommendations for how cyber security policy should be written and implemented if it is to truly be secure, e.g. to protect human rights.

  80. (2016)  Seven Continents: A Telecom Informer World Tour   - TProphet
    • As The Telecom Informer, TProphet has traveled all over the world and visited all seven continents.  Everyone knows that different countries have different cultures, but did you know that there are different telephone cultures?  The way that people use and interact with telecommunications services is different all over the world.  Learn about some of the off-the-beaten-track places he has visited (such as Antarctica, Ecuador, Myanmar, and North Korea) and how, no matter where you live, phones bring the world closer together.

  81. (2016)  Show Networks   - John Huntington
    • Behind the scenes on most any large entertainment production today - from an arena spectacle to a theme park dark ride, from a concert tour to a Broadway stage - you will find Ethernet switches, cat 5 cables, and IP addresses all playing a critical role carrying a variety of control protocols that make these sophisticated shows possible.  In this talk, John Huntington, author of Show Networks and Control Systems, will give an overview of the ways that networks are used on shows, and why and how we use equipment from traditional IT applications.  In addition, applications from real shows will be featured, including a detailed exploration of the sophisticated control network for the Gravesend Inn haunted attraction.

  82. (2016)  The Silk Road to Life without Parole - A Deeper Look at the Trial of Ross Ulbricht   - Joshua Horowitz, Andy Greenberg, Alex Winter
    • Join Joshua Horowitz, one of Ross Ulbricht's defense attorneys, tech journalist Andy Greenberg, and filmmaker Alex Winter for an in-depth discussion of the Silk Road case.  All panelists attended Ulbricht's trial.  Greenberg has written extensively about the now legendary black market's rise and fall and Alex Winter directed the documentary Deep Web, with exclusive access to the Ulbricht family and defense team.  In this panel discussion, they'll examine the less-discussed aspects of Ulbricht's case, including the role of two corrupt federal agents in the Silk Road investigation, the indictment of Ulbricht's alleged mentor and consigliere Variety Jones, and Ulbricht's controversial life sentence without parole.

  83. (2016)  Smart Cities and Blockchains: New Techno-Utopian Dreams or Nightmares?   - Burcu Baykurt, James Cropcho, Benjamin Dean
    • History is littered with techno-utopian visions, particularly those of powerful American industrialists.  Henry Ford's Fordlandia, Walt Disney's Epcot, Peter Thiel's Seasteading.  Technologies play a recurring role in inspiring and enabling these attempts to forge or impose new governmental and/or social relations.  Techno-utopian dreams are once again emerging in the form of sensor and data-driven "smart" cities and decentralized, blockchain-based organizations.  What are the similarities and differences between techno-utopian visions over time?  What role does technology play in forming and operationalizing these visions?  Who ultimately defines what a perfect society is?  How does this determine whether the techno-utopian visions end up as dreams or nightmares?

  84. (2016)  Social Engineering   - Evil Corley and Friends
    • Since 1994, we've had a lot of fun with this panel, where we not only share stories of some of our most memorable social engineering adventures of years past, but we try and create some new memories live on stage over a good old-fashioned telephone line.  For those not familiar, social engineering is the art of getting information out of people, information that you usually have absolutely no business possessing.  The ability to gain a stranger's trust, knowing what to ask for, and (perhaps most importantly) how to deal with failing miserably are all vital skills in the pursuit of unauthorized information.  This panel is open to suggestion on targets to try, as well as open to new panelists who want to share their stories and skills.  Leave your info at the information desk.  (Be sure to include your Social Security number and mother's maiden name.)

  85. (2016)  Spy Hard with a Vengeance: How One City Stood Up to the Department of Homeland Security  - aestetix, Brian Hofer
    • This talk will cover the reign of surveillance that has secretly taken over the United States at the local level through use of federal grant money, and offer suggestions on how we can fight back.  It's the story of how the Department of Homeland Security (DHS) tried to create a fusion center in Oakland, California.  In particular, the presentation will share details of the Oakland privacy policy the speakers helped create in response to this intrusive spy system, and the advocacy that led to its creation.  The hope is to teach the framework that was created, shed light on how these issues affect both Americans and Europeans, and show how businesses and governments can find a balance between security and privacy.

  86. (2016)  Stealing Bitcoin with Math   - Filippo Valsorda, Ryan Castellucci
    • Bitcoin is the best thing that ever happened to bored applied cryptographers: it's a public database of keys and signatures made by quickly developed software that, when broken, drops money as if it was loot.  This talk will look at mistakes old and new that enabled attacks: from ECDSA repeated nonces to using Math.random to make keys, from double spending and transaction malleability to crappy brainwallets.  The bad news is that most vulnerable wallets were emptied a long time ago.  The good news is that we get to look at how (and how fast) "cryptocriminals" operate in the process.  In any case, new tools that implement some of the attacks will be demoed and released.  No need to be a Bitcoin or crypto wizard - everything you need in order to understand what those poor victims didn't will be explained.

  87. (2016)  Sunset or Evolution of the PSTN?   - Fred Goldstein
    • The Public Switched Telephone Network (PSTN) has seen better days.  With interest diverted to the Internet and mobile services, the venerable PSTN that we know and love seems like it's ready for the knackers.  But maybe that's not quite right.  True, the dominant carriers have let their wireline networks rot, and the TDM technology that seemed so advanced two decades ago is this year's black-and-white TV set.  But the PSTN has undergone many rounds of evolution, from cord switchboards to Strowger dial to common control to analog ESS to digital.  Now SIP signaling and IP networks are taking over.  It's the big carriers who want to claim that this is no longer the PSTN so that they can get out of their regulatory obligations and exercise their remaining monopoly muscle.  And the folks in Washington who are supposed to be supervising this still haven't figured out what VoIP is, so no wonder it's all such a mess.  Let's see where the PSTN is going and what that means to us.

  88. (2016)  Surveillance Gives Me Chills   - Alex Marthews
    • In surveys, users say that government surveillance affects their online behavior, but users could always be lying.  Join Alex as he takes you through the latest research on the effect of surveillance on actual user behavior - some of it his own - and connects this research to government and corporate efforts to chill and censor "extremist content" on the Internet.

  89. (2016)  This Key is Your Key, This Key is My Key   - Deviant Ollam, Howard Payne
    • We all know that the four most common passwords are love, secret, sex, and god.  Like default passwords, locks are often keyed alike for convenience, perceived safety, or for economic and other reasons.  This talk explores the idea of "popular keys" and how many lock systems are secured by easily guessable keys.

  90. (2016)  The TSA Keys Leak: Government Backdoors and the Dangers of Security Theater   - DarkSim905, Johnny Xmas, Nite 0wl
    • In late 2015, hackers revealed yet another threat to American privacy, but this time it hit far closer to home than credit cards and Social Security numbers.  The master keys the TSA uses to inspect all luggage being placed on an airplane were now available to anyone with a 3D printer!  Three of the primary contributors to the leak and the subsequent reproduction of those keys will discuss their trials and tribulations during the event, including why government backdoors like key escrow are a really bad idea, the preposterousness of 3D printing keys in the first place, how the media completely missed the point of the entire operation, and how journalism doesn't actually even exist anymore.  This will be a comprehensive discussion of literally every aspect of the TSA keys leak from top to bottom, including the release of previously undisclosed research.  No talk of this magnitude has been given at any con on this topic!  Notice: This talk will include the first public release of a brand new master key!
    • TSA Travel Sentry Master Keys

  91. (2016)  Tuning in to New York City's Pirates of the Air   - David Goren
    • Pirate radio in New York City is a homegrown cultural phenomenon that is at once aesthetically vibrant, technologically tumultuous, and undeniably illegal.  Emanating from clandestine studios and hidden transmitters, the sounds of Kreyol, Yiddish, Spanish, and Caribbean-accented English waft into the urban atmosphere.  On an average night in Flatbush, Brooklyn, it's not uncommon to be able to hear as many as three dozen pirate stations between 87.9 and 107.9 MHz.  This flowering of outlaw micro-radio stations in Brooklyn and throughout the greater New York City region is a major disruption to the status quo of corporate controlled, robo-playlisted mega stations   Their unregulated presence and programming often reflects the throb and hum of a diverse city more authentically than traditional media outlets.  Join radio producer David Goren for an audio tour of these stations featuring the music, programs, and personalities that make up New York City's pirate radio scene.

  92. (2016)  Understanding Tor Onion Services and Their Use Cases   - asn, Nima Fatemi, David Goulet
    • In the last few years, we've seen more and more interest in Tor onion services (a.k.a. Tor hidden services).  They are used by press to host whistleblowing platforms, by activists who want to set up a website that authorities want to shut down, by service providers to offer more security to their users, and for tons of other uses as well.  This panel will be presenting the technical aspects of Tor onion services as well as interesting use cases.  As the onion service protocol aged, weaknesses started to appear in its design.  For this reason, the speakers have been working since 2013 on the next generation onion service protocol.  You'll get a status update on their progress, an explanation of the improvements it brings, and also why it is greatly needed.

  93. (2016)  What Really Happened?  Fact, Truth, and Research Techniques   - Evan Koblentz
    • Anyone can tell you something is true because they "researched" it.  Evan will present some methods of performing historical research that stand up to challenges.  Some of the methods are useful for social hacking, however the scope does not include any coding or technical subjects.

  94. (2016)  What the F*ck Are You Talking About?  Storytelling for Hackers   - Johannes
    • Humans are storytelling beings.  From the moment the primordial ooze Mendelized itself into something like consciousness, we have been telling yarns: about the harvest, about the Gods, about the giant cats that wanted to eat us.  But - for f*ck's sake! - hackers are bad storytellers.  Misunderstood by the media (and we're not even talking about the mainstream press!), ripped apart by their own peers, often incomprehensible and boring.  But whhhhyyyy???  What's going on in the hackersphere is probably shaping the future of our civilization.  Narratology refers to both the theory and the study of narrative, and narrative structure and the ways that these affect our perception.  You should come and listen, because it might save our movement - and more.

  95. (2016)  What the Hack?  Perceptions of Hackers and Cybercriminals in Popular Culture   - Aunshul Rege, Quinn Heath
    • How are hackers portrayed in the media?  What are the typical stereotypes?  How does the hacking community feel about the term "hacker," gender portrayals, and depictions in movies and television shows?  This panel hopes to answer all of these questions and more!  Aunshul and Quinn were at HOPE X, talked to attendees then, and asked about their thoughts on the ways hackers were presented in the media.  They are now back to share what they've found and to get more of your thoughts!  Expect lots of interaction, conversation, and (possibly) heckling.

  96. (2016)  When Vulnerability Disclosure Turns Ugly   - Sam Bowne, Alex Muentz
    • Sam was accused of illegal hacking in the SC Magazine article "Professor Hacks University Health Conway in Demonstration for Class."  That article made a mess so big, it took a real lawyer, Alex Muentz, to clear it up.  Sam will explain how this happened and Alex will then explain how he handled this and offer informed advice on the laws around vulnerability disclosure, along with how to use the media effectively.  In addition, Alex will describe a few other cases where attempts at responsible disclosure went wrong, what had to be done to fix it, and how the disclosure should have been done.

  97. (2016)  Who's Killing Crypto?   - Amie Stepanovich, Drew Mitnick
    • Governments have gotten really good at coming up with ways to undermine encryption.  They can outright ban the use of certain types or strengths, place trade restrictions, mandate the insertion of backdoors or vulnerabilities, work with companies directly to undermine the encryption standards, arrest executives for failing to comply with orders, and seek assistance from courts through antiquated, off topic laws.  In this presentation, Amie and Drew will compare various approaches and provide the historical context that better illustrates how and why such restrictions are doomed to either fail or worsen the state of digital security.  The session is planned to be part history lesson and part overview of the current state of encryption debates.  The discussion will include where panelists think the law of encryption should and will go, and provide details on the campaigns that have been run at Access Now to promote the unrestricted use of encryption.

  98. (2016)  Women in Cyber Security   - Renee Pollack, Debora Gondek, Kathleen Seubert, Morgan Strobel, Cindy Cullen
    • With 11 percent of the cyber security workforce being women, why is it important to encourage women to be involved?  How is security done differently by women or is it?  This panel consists of women in different phases of career: just graduated college starting first professional job, mid-career, and experienced professional.  Each panel member will provide an overview of their perspective on the workplace, including if they have experienced discrimination, how best to survive and thrive, and when it is time to move on.  Attendees will learn how others have responded to specific incidents, managed work life balance, become aware of how they may be making the environment feel hostile, and dealt with potential legal implications of their actions, and will also learn why having a diverse employee pool is good for the organization and for fellow employees.

  99. (2016)  Your Level-Building Tool is Our Sound Stage   - Tamara Yadao, Chris Burke, Jeremy Pesner
    • Game art duo "foci + loci" (Tamara Yadao Chris Burke talk about hacking immersive video game spaces.  Over the last six years, they have been using Little Big Planet to build and break custom game environments for live music performance.  Joined by multidisciplinary technologist Jeremy Pesner, they will demonstrate and take apart some of their stranger maps and virtual instruments like the Tiltofon, the Flotrillium, and the Anytime-inator, while discussing successes and failures arising from repurposing or pushing game level-building tools beyond intended uses.  They will raise questions about hacking the "look and feel" of game spaces and how it relates to professional game development tools like Unity and the Unreal Engine versus off-the-shelf games like Little Big Planet, Minecraft, or Portal.  They will also look at Machinima (using game engines to create cinema) as an early strategy of video game appropriation and its relationship to culture jamming and hard/soft hacking in the gaming community.  Lastly, they will present a sneak peak of the upcoming musical-in-game-space, Songs from the Robot Apocalypse, featuring the Arachnobot, the flying Toasterbot, and a robot made from a classic Game Boy DMG-1.

  100. (2016)  Closing Ceremonies  - Evil Corley
    • We've finally gotten a bill before Congress designating the Monday after HOPE as a day when one doesn't have to go to work or school.  Many employers already recognize as fruitless any expectation that work will get done on that day.  So don't feel bad about staying late on Sunday in order to attend our final session of the conference - the infamous HOPE closing ceremonies.  This is where we go over what went right and what went wrong this weekend - and where we let you know what we had to go through in order to pull this whole thing off.  And, if we're not totally fed up and disgusted, there may be talk of a sequel.



The Circle of HOPE





  1. (2018)  $500 Billion Broadband Scandal: It's Time to Break Up AT&T... Again  - Bruce Kushnick
    • America was supposed to be a fiber optic nation and the telecom pipes were supposed to be open to all forms of competition.  Customers paid over half a trillion dollars to make this happen by 2018 - and that's the low number.  Through mergers and the takeover of the FCC and some state commissions, today there are only a few companies that have taken control of most of America's broadband, Internet, cable TV, phone, satellite, and wireless services.  How do we fix net neutrality, get back our privacy, stop the overcharging, and finally get gig speeds and open pipes?  Hear how to hold them accountable for their misdeeds and take the final step: It's time to break up AT&T, Verizon, and the cable companies... again.

  2. (2018)  Accessibility, Dammit!  - xio
    • Accessibility is for everyone, and yet not everyone is for accessibility.  Security has gone from being a layer atop existing products to a ubiquitous and pervasive presence in information technology.  Accessibility should be second nature as well.  This talk will delve into the subject and discover where progress is being made and where it is failing, where we are and what is on the horizon, how it overlaps and how it complements other tech fields, and why you should be for accessibility too.

  3. (2018)  "And This Is It?" - What Went Wrong with Surveillance Reform After Snowden*  - Jeff Landale, Sean Vitka, Marcy Wheeler, Sue Udry, Alex Marthews
    • After the passage of the USA Freedom Act, former NSA director Michael Hayden was flabbergasted at the lack of restrictions placed on the NSA.  "And this is it after two years?  Cool!"  What happened?  The panel will discuss the failures of the post-Snowden surveillance reform movement and examine the divergences and conflicts between think tanks and grassroots organizations on strategy, tactics, and goals that allowed the surveillance reform sphere to fail to capitalize on the massive public interest in domestic and global spying.

  4. (2018)  ArduTouch Music Synthesizer Kit: Music Generation for Newbies  - Mitch Altman
    • This is an inexpensive Arduino-compatible musical instrument with a touch keyboard, amp, and speaker that anyone can make.  It is easy to build - designed for total beginners to learn to solder together.  It's a very low cost method for making music/sound/noise, and a fun way to learn Digital Signal Processing (DSP) for generating music/sound/noise.  This talk will show beginners how the ArduTouch music synthesizer kit makes use of DSP to create its large diversity of music/sound/noise.  Mitch will also explain how the touch keyboard works, as well as the cheap amplifier/speaker built into the board.  The ArduTouch Arduino library works on any Arduino board and Mitch will demonstrate how to make use of this library to create your own unique synthesizers - both by hacking some of the many examples it comes with, or by making use of its high-level functions.  This talk will also include a demo of some of the music the ArduTouch can make, as well as some wonderful nasty noise!

  5. (2018)  Ask the EFF: The Year in Digital Civil Liberties  - Kurt Opsahl, Vivian Brown, Bill Budington, Sydney Li, Cooper Quintin
    • Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation's premiere digital civil liberties group fighting for freedom and privacy in the computer age.  This session will include updates on current EFF issues, such as the government's effort to undermine encryption (and add backdoors), the fight for network neutrality, discussion of EFF's technology projects to spread encryption across the web and emails, updates on cases and legislation affecting security research, and much more.  Half the session will be given over to question-and-answer, so it's your chance to ask EFF questions about the law and technology issues that are important to you.

  6. (2018)  ATT&CKing with Threat Intelligence  - Cody Thomas, Christopher Korban
    • MITRE's ATT&CK is a community-driven knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary's life cycle and the platforms they are known to target.  By scoping the wide breadth of the MITRE ATT&CK matrix to focus initially on the techniques used by threat actors you specifically care about, you can help the defenders create more useful and impactful detections first.  Once you start emulating the appropriate threat actors, you can practice your defenses in a scenario that's more realistic and applicable without the need for an actual intrusion.  The speakers are providing a process and a case study of APT3 - a China-based threat group - for how to go from finding threat intelligence, sifting through it for actionable techniques, creating emulation plans, discovering how to emulate different techniques... to actually operating on a network.  They are also providing a beginning "cheat sheet" for this actor to give a starting point for red and blue teams to accomplish these techniques in their own environment without the need to build their own tooling.

  7. (2018)  Autocrypt: End-to-End Encrypted Email for Everyone  - Daniel Kahn Gillmor (dkg)
    • Autocrypt is a user-centered, developer-driven effort to make a set of standards that support convenient, usable, easily-adoptable end-to-end encrypted email.  With multiple email programs participating, they aim to make interoperable tools that actual humans can easily use.  Compared with existing email encryption schemes, Autocrypt involves a number of minor heresies, all aimed at simplicity of user experience and avoiding surprising failure modes.  This talk will explain the differences between Autocrypt and other schemes, highlight the state-of-the-art (including some demonstrations), and talk about what comes next and how to get involved as a user, a trainer, or a developer.

  8. (2018)  Barrett Brown Onstage Interview  - Spencer Ackerman
    • Writer and anarchist activist Barrett Brown was prosecuted and sentenced to 63 months in federal prison and nearly a million dollars restitution after posting a link to a URL where stolen emails of private intelligence agencies were already online.  He will be interviewed onstage by award-winning journalist (((Spencer Ackerman))), who is currently a senior national security correspondent for The Daily Beast.  This freeform interview will cover a variety of topics, likely to include Brown's alleged past connections with Anonymous and LulzSec and their reported exfiltration and sharing with WikiLeaks of a huge trove of stolen emails and other sensitive info from private intelligence agencies HBGary, Infragard, and Endgame Systems.  This data exposed collusion between U.S. government law enforcement and intelligence agencies with private sector intelligence agencies that have no public oversight.  An audience Q&A will follow.

  9. (2018)  Basement MEMS: Tools, Processes, and Techniques for Producing Microelectromechanical Systems on a Shoestring  - Dave Arney
    • MEMS devices include microfluidics, pressure and motion sensors, and actuators like valves and comb motors.  We usually think of them as black boxes that arrive packaged up like integrated circuits.  In this talk, Dave will share some experiences, equipment designs, and early results with creating small silicon parts in a home lab.  Semiconductor manufacturing equipment is available cheaply on secondhand markets, and processes that were state-of-the-art are now achievable on a small budget and without the infrastructure requirements of large scale production.  Together with open lab hardware and accessible microcontrollers, this puts MEMS fabrication in reach for the maker community.

  10. (2018)  Being Mean to Software Patents  - Daniel Nazer
    • EFF has a "Stupid Patent of the Month" blog series, which highlights some of the silliest patents and the most destructive patent troll campaigns.  It has also gotten EFF sued - twice.  People don't like it when you say that their stupid patents are stupid.  Fortunately, both times EFF fought back and won.  But how is the policy battle going?  Did the Supreme Court get rid of software patents in a 2014 decision?  Is the USPTO still churning out terrible patents?  Will Congress do anything?  This talk will revisit some of the greatest hits from the Stupid Patent of the Month series and give you the big picture about the fight against software patents.

  11. (2018)  Breath of the RF Field: Hacking Amiibo with Software-Defined Radio  - James Chambers
    • Amiibo are Nintendo's "toys to life" product line, supported by the 3DS, Wii U, and Switch.  Interested in seeing whether these figures could be used to exploit games or consoles, James decided to make an Amiibo simulator and fuzzing tool using software-defined radio.  This talk will provide an in-depth look at the technology and proprietary security system behind Amiibo, as well as the process of reverse engineering it.  He'll also explain the development of the simulator using a Proxmark3, and how he used it to find a bug in the NFC protocol used by the Switch and Wii U.

  12. (2018)  Chelsea Manning Onstage Interview  - Yan Zhu
    • Chelsea Manning, a former intelligence analyst for the U.S. Department of Defense who disclosed a trove of classified documents to WikiLeaks revealing human rights abuses and corruption connected to the U.S. wars in Iraq and Afghanistan, will speak onstage with noted technologist Yan Zhu on a variety of topics - including the ramifications of government secrecy, the need for greater government transparency, his experiences being charged and court-martialed for violations of the Espionage Act, and serving seven years in military prison before receiving a commutation of her 35-year sentence by the President of the United States.  An extended audience Q&A will follow.

  13. (2018)  A Conversation on Internet Censorship  - Roya Ensafi, Ksenia Ermoshina, Sergey Frolov, Lex Gill, Will Scott
    • The Internet around us is increasingly regulated and censored.  Censorship is present across the web - influenced by law, politics, activism, and corporations.  This panel discussion will highlight some of the successful strategies being used to understand online censorship and to support our voices in the online forum.  The conversation will cover recent events that impinge our online speech, and what we can do about it.

  14. (2018)  Creating a Radio Time Machine: Software-Defined Radios and Time-Shifted Recordings  - Thomas Witherspoon
    • Since the earliest days of radio transmitting, individuals and organizations have made an effort to record and preserve radio signals in the form of broadcasts and other over-the-air communications, especially those of historical significance.  Now low-cost Software-Defined Radios (SDRs) coupled with today's faster memory-enhanced computers allow us to record not just individual signals from one radio station at a time, but an entire broadcast band - a wide swath of frequencies - all at once.  Each recording from a particular day and time can easily contain dozens, if not hundreds, of stations broadcasting and communicating simultaneously.  Later, via a software-defined radio application, recordings can be tuned and listened to (decoded) as if they were live.  This talk will discuss how you can build your own "radio time machine" which supports such virtual time shifts by utilizing an inexpensive ($25-$100) SDR, and also show how you can - for free - virtually "travel" through recent history on radio archivist's preexisting radio time machines.

  15. (2018)  Crossing the Border in the Age of Trump  - Bill Budington, Kurt Opsahl
    • When we travel, we bring our lives with us.  From financial records and personal photos to account passwords and even digital wallets, the information we carry on our devices can be extremely sensitive, and gives anyone with access to it an enormous amount of power over us.  At the same time, TSA and border agents have shown increasing interest in gaining access to this information, putting us in a compromised situation and disrupting our travels.  This talk will cover the legal protections that you have, and what you can do before, during, and after you travel to protect your data from prying eyes.  This includes the legal and practical precedents that have been established when crossing both domestic and international borders, the technological capabilities of border agents, techniques that are likely to become more prevalent, and what tools you have in your digital toolbox to ensure your data is kept safe.

  16. (2018)  Cybersquatting on the Trump Campaign: A Bizarre Tale of Real Fake News  - Alexander J. Urbelis
    • This talk will reveal and discuss a disinformation operation that was gearing up to attack the Trump campaign during the summer of the 2016 presidential election.  Trump's surprisingly competent information control operation detected and halted the attack.  Alexander will discuss how he and his law firm pieced together evidence of the disinformation attack and the Trump campaign's countermeasures by collecting and analyzing DNS-related data.  This talk will involve a fascinating and bizarre set of characters and settings, including psychics, preachers, lawyers, gamblers, conspiracies, mystical locations, and of course, domain names, DNS data, and quite a few active threats.

  17. (2018)  Dark Caracal: How to Burn a Spy Agency and Get Away with It  - Cooper Quintin
    • The nature of state surveillance is changing, and "cyberwar" is becoming cheaper.  Stuxnet, Fancy Bear, and WannaCry are some of the more infamous examples of state-sponsored hacking.  But what happens when a nation state on a shoestring budget wants to run a global espionage campaign?  And more importantly, what happens when they are stupid about it and get caught?  This talk will discuss the changing nature of state surveillance, the details of a new state-sponsored malware campaign uncovered by EFF and Lookout, and what hackers can do to stop governments engaging in targeted digital surveillance.

  18. (2018)  The Demoscene: How Software Piracy Birthed an Underground Art Scene  - Inverse Phase
    • Have you ever used old, pirated software and found it came with an "extra" introduction from the person who broke the copy protection?  Have you ever watched a music video stored entirely in mere kilobytes of space?  There's a whole community of individuals called the Demoscene trying to make art under extreme limitations, whether it be 3D graphics on an 8-bit Atari, or CD-quality music playback on a Commodore 64.  This presentation will explain how that scene came to be, what it consists of now, and of course you'll see some example demos!
    • Immediately after the Demoscene talk, Inverse Phase will commandeer the big screen for two hours of the most mind-bending demoscene productions ever created by hackers from around the globe.  Take a trip through the evolution of demos (an underground art scene born out of software piracy) from the scene's early beginnings in the mid 1980s, to the golden era of demos in the 1990s, and the modern era where we ended up!  Expect a chill vibe with brief introductions of each demo as they play on the big screen.  If you've never seen this stuff, you really owe it to yourself to check it out.

  19. (2018)  The DMV and You: Where Identity Meets The Road  - Aphrodite
    • Nearly everyone in the United States and Canada interacts with these agencies whose reputation is linked with Patty and Selma from The Simpsons.  The modern DMV isn't simply a place to get a card with your picture on it.  They are arbiters of identity in these countries without national IDs.  In this talk, Aphrodite will provide a unique inside view into the operations you don't normally hear about, such as facial recognition, the REAL ID Act's consequences, and high tech details of thei plastic or polycarbonate cards in your wallet.

  20. (2018)  EMP, CME, and the Electronic Apocalypse  - David Cripe
    • With continued geopolitical unrest among nuclear powers and the total ubiquity of electronics in every aspect of modern life, there is a concern over catastrophic events that could have the potential to disrupt and alter life as we know it.  The threats of Electromagnetic Pulse (EMP) and Coronal Mass Ejection (CME) are real and, should they occur, the results would impact the lives of millions.  The physics behind these threats are analyzed, their effects and potential for damage estimated, and means to protect against them examined.  Additionally, the use of EMP as a weapon is analyzed from a strategic standpoint, and non-nuclear threats to the electrical grid considered.

  21. (2018)  The Encrypted Notes of Antonio Marzi  - Anna Bernardi, Filippo Valsorda
    • Antonio Marzi died in 2007, leaving behind dozens of encrypted notes and a partial key.  During World War II, he chose to work with the British Special Operations Executive and was parachuted into Italian territory under German occupation.  There he transmitted detailed military-related dispatches in encrypted form.  This was not modern cryptography, nor Enigma, but the kind that was doable on the field with pen and paper.  Specifically, they used poem codes, as Between Silk and Cyanide tells us: a double columnar transposition cipher that scrambles the order of the letters.  Marzi sent the notes to an Italian professor and there they stayed undeciphered until 2013.  Anna and Filippo obtained copies of the notes and exploited one of the mortal sins of cryptography, key reuse, to reconstruct the key.  (Armin Krauss independently decrypted the notes in the same year.)  A number of them were indecipherable due to encryption mistakes made in the field.  During the war, entire departments hacked away at these ciphertexts, but today computers make easy work of them.  This talk will explore how they went from recognizing the code, to reconstructing the key (partially thanks to little handwritten dots), to the contents of the notes.

  22. (2018)  End of File  - Jason Scott
    • Every file has an end, every hard drive goes bad, and every carrier eventually drops.  What matters is what we do when these expected (or unexpected) ends arrive.  Jason Scott of the Internet Archive and Archive Team talks about endings, near-misses, and confronting finite resources and energy in a variety of situations that demand infinite amounts of attention, effort, and meaning.  Expect humor, sadness, overviews of moving day logistics and a hint of angel wings.

  23. (2018)  ENIAC: The Hack That Started It All  - Brian L. Stuart
    • The ENIAC was dedicated on February 15, 1946 and became the testbed upon which people learned to build and program powerful digital computers.  It became a national resource, contributing to a wide variety of R&D until it was decommissioned ten years later.  ENIAC was designed and built at the University of Pennsylvania in Philadelphia, using 18,000 vacuum tubes consuming 150,000 watts of power.  This presentation will focus on how the ENIAC was conceived, designed, built, and worked; how it was used in different modes of operation; and the details of its internal operations.  This will be illustrated in real-time with a fully functional, interactive, and photorealistic ENIAC emulator created by the speaker.  The significance and relevance of the ENIAC to computers we use today will also be discussed.  A brief audience Q&A will follow.

  24. (2018)  The Enron Email Corpus: Where the Bodies Are Buried?  - David Noever
    • As the biggest public domain email database, the Enron email corpus details financial deception in the world's largest energy trading company and, at the time in 2002, triggered the most costly U.S. bankruptcy and its most massive audit failure.  What can Enron tell us today?  This talk will invite fresh perspective on how email has (and has not) changed since 2002.  Can modern forensic methods find where any new email bodies are buried, even when scanning through the evidence of a previously closed case?  The presentation highlights some funny and poignant examples of how humans in business suits write to each other when planning mischief.  For the previous six years prior to its failure, Fortune Magazine had named Enron as "America's most innovative company."  Enron's former chief financial officer now lectures profitably to business groups and hedge funds using a new self-appointed title of "chief loophole officer."  More than 3,000 studies have dissected Enron's email, but have failed to uncover some of its more fascinating forensic artifacts.  Nearly two decades later, we revisit this trove to discover what modern tools can do with it.
    • For instance, when the Federal Energy Regulatory Commission (FERC) originally released two terabytes (1.6 million emails and attachments), they claimed to have stripped all personal information.  Yet a modern machine learning pipeline in 2018 can identify almost 50,000 previously unreported instances, including credit card numbers, bank accounts, and additional evidence that potentially harms the 99 percent of Enron employees who were never charged.  At least one example of detectable malware is still included in the official Enron corpus (called "Joke-StressRelief") along with 231 other executables which continue to accompany each download.  This talk will further investigate whether by using email traffic alone, machine learning can predict all of the (eventually charged) persons of interest.  It will discuss how Hadoop distributed processing on multiple, clustered virtual machines was deployed.  More than 50 algorithms were analyzed for both accuracy (90 plus percent) and execution times.  In compliance with new (June 2018) European privacy rules for explainable artificial intelligence, each algorithmic decision was reduced to human-understandable rules and rank order to define which email factors might prove most predictive to future fraud and conspiracy investigations.

  25. (2018)  Evidential Study of IoT Botnets - The Bad and The Ugly!  - Aditya K. Sood
    • IoT botnets are deployed heavily to perform nefarious activities by circumventing the integrity of the IoT device to launch sophisticated targeted or broad-based attacks.  IoT botnets have enhanced the cybercrime operations to a great extent, thereby making it easier for the attackers to carry out unauthorized activities on the Internet.  In this talk, Aditya will perform an empirical analysis to conduct a characteristic study of IoT botnets to understand the inherent design, architecture, and associated operations.  Code samples will be dissected to highlight the inherent nefarious operations performed by the IoT bots.  The study covers analysis of multiple IoT botnet families.

  26. (2018)  Four Arguments on Why State Hacking is Bad  - Luca Follis
    • While state hacking is a powerful weapon for authoritarian regimes, it has an erosive effect on democratic states.  Hacking is advantageous for authoritarian governments that need to retain domestic control, monitor and disturb dissent, attack aggressors, and project force internationally.  State hacking is bad because it is deleterious to the legitimacy of the democratic state, the legal system, "ethical" capitalism, and the democratic process itself.  In this talk, the argument is presented that state hacking is bad for democratic elections, the integrity of the security services, transparency in government, privacy for the individual, the separation of public and private militaries, the judicial system, and the development of ethical cybersecurity practices.  Such hacking is a short circuit in the rule of law and undermines the machinery of democracy.  State hacking is bad because it provides unparalleled advantage to rulemakers while delegitimizing the citizen led government.

  27. (2018)  Free Expression, Privacy, and the Role of Tech Companies: Where Do We Go From Here?  - Laura Reed
    • From the proliferation of dangerous speech online to massive data breaches to the Facebook Cambridge Analytica scandal, it's clear that tech companies' policies and practices can have a significant impact on people's ability to exercise their rights to freedom of expression and privacy.  Yet companies aren't doing enough to protect these rights.  How can they do better and how can we incentivize them to move in the right direction?  Ranking Digital Rights, a nonprofit research initiative, works with an international network of partners to set global standards for how companies in the information and communication technology sector should respect freedom of expression and privacy.  Its annual corporate accountability index ranks 22 companies on a set of indicators evaluating how transparent companies are about their commitments and policies affecting human rights.  This talk will give an overview of how the corporate accountability index lays out a road map for companies to improve their human rights standards.  Laura will provide highlights from the recently launched 2018 index, showing where companies are beginning to be more transparent about their practices - things like content moderation policies and practices for handling user information - and where there are still significant gaps in disclosure that leave users in the dark.

  28. (2018)  Free Geek Panel - Reusing and Recycling Old Computers For Fun and Nonprofit  - Dan Bartholomew, Ryan Fukunaga, Zachary (Zac) Slade, Charlie Coile, Joel Izlar
    • Across North America, passionate people help out at their community Free Geek (or a similar organization) to refurbish discarded computers and make them useful tools again for people who need them.  In the process of this, people build community, gain skills, and help the planet.  Challenges to successful operations include ethical e-waste recycling practices, troubleshooting and repair, parts management, drive imaging, ensuring Free and Open-Source Software (FOSS) use, managing volunteers, organizational structure and governance, financial sustainability, and ensuring a balance between community needs and interests.  Participants from Free Geek and similar organizations will discuss these challenges, with success stories and wrong turns, and how they manage to keep the doors open and lights on to serve the public good.

  29. (2018)  Futel: The Payphone, Devolved  - Karl Anderson
    • Part public service and part public art, Futel is keeping payphones alive by installing them in public locations and providing free telephone service, telephone-mediated art, and live human interaction.  They feel that the constraints of the phone interface spur creativity, pay homage to a generation of creative hackers, and allow them to worm their way into the minds of large groups of people.  Now that we are finally living in the cyberpunk dystopia promised in the 1980s, they are poised to seize this moment.  You will learn what aspects of the project make it effective, and how they can be applied to other creative technological projects.
    • Telecom Informer  - Overview of Futel, a public arts organization in Portland, Oregon dedicated to preserving and maintaining public telephone hardware and offering free phone and basic information services, by The Prophet
    • What is Futel?  - Futel is a free telephone company.  They offer domestic calls, messaging, human interaction, connections to services, and interactive challenges.  All services are free of charge and accessible from any Futel telephone, by Karl Anderson

  30. (2018)  Go FERPA Yourself: Checking Your Student Record  - Adam Goldstein
    • Your student record is available to law enforcement, the military, and professional licensing boards - but do you know what it says about you?  There's a law for that: the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. Sec. 1232g).  This session covers the mechanics of how to request your record, how to handle some of the ways colleges have tried to wiggle out of turning those records over, and the process for disputing incorrect information (including how to tell if those records are already in the possession of law enforcement).

  31. (2018)  Hackers and Shamans - Travelers of the Black Box  - danae valentina
    • A session to critically analyze the figures of the hacker and the shaman, their ontological similarities and their journeys as travelers of their respective "black boxes" - the computational network in the case of the hacker and the human conscience in the case of the shaman.  This talk will delineate modes of direct action that would allow us to think about hacking as a way to overcome ruling knowledge paradigms.

  32. (2018)  Hackers Got Talent  - Jason Scott and Friends
    • Do you have a cool talent or hack?  Here's your chance to present it onstage to a large audience of enthusiastic hackers, hosted once more by hacker archivist Jason Scott.  Onstage hacks will be judged by a combination of panelists and audience.  First place wins a valuable prize!

  33. (2018)  Hacking Extradition: Fighting the Long Arm of U.S. Law  - Nathan Fuller, Grace North, Lauri Love, Barrett Brown
    • The United States punishes computer crimes more severely than any of its western allies, often threatening to imprison digital dissidents for decades for crimes other countries would sanction with fines or probation.  Preventing the U.S. from extraditing alleged hackers across the pond could mean saving a defendant's life.  Earlier this year, U.K. security researcher Lauri Love successfully beat back the U.S.'s attempt to extradite him from Britain, in a redux of Gary McKinnon's ten year extradition battle which resulted in the "forum bar" that helped protect Love.  But the judges in Lauri's case went further than protecting only him: The High Court's ruling condemned the conditions of U.S. prisons, citing dangerously inadequate mental healthcare as a reason to keep Lauri in the U.K.  Using his ordeal as a case study, we can see how these extradition cases can have meaningful ramifications beyond a single defendant.  Lauri Love, Gary McKinnon, and Richard O'Dwyer have recently shown how to stand up to the United States' perceived global reach.  How can we learn from these cases to protect others facing extradition?  Can we turn a U.K. court ruling into meaningful U.S. prison reform?

  34. (2018)  Hacking Healthcare: Bringing a Hacker Mindset to Solving Healthcare's Biggest Problems  - Dave Arney
    • The Institute of Medicine estimates that up to 400,000 Americans are killed by preventable medical errors per year.  Better patient monitoring, smart alarm systems, advanced treatment algorithms, and data analytics are key technologies that can help to reduce this number.  Attempts to build better systems run into common problems including the difficulty of integrating into existing workflows, manufacturer-specific silos, and a lack of data to help drive improvements.  Solving these problems requires people who can connect things together in new and unlikely ways, holistically examine processes that involve both technology and human workflows, and find creative ways to get things done.  This talk will discuss why healthcare can be a difficult place to be an engineer, some possible reasons that clinicians may be unwilling to implement your perfectly reasonable solutions, and how a hacker mindset is essential for improving the safety and effectiveness of healthcare.

  35. (2018)  "Help!  My Toaster's Attacking Me!" and Other 911 Calls of the Future: An Update on the Legal and Policy Landscape for the Internet of Things  - Harley Geiger, Amie Stepanovich
    • The Internet of Things is expected to grow to more than 200 billion devices by 2020.  Unfortunately, the market has not incentivized strong security for most IoT products, and the legal and regulatory environments - not surprisingly - have not been able to keep pace with the technology.  This talk will detail the potential growth of the Internet of Things, focusing on the exploration of key legal and policy developments related to IoT security.  Included will be updates on relevant court cases, legislative proposals, and regulatory activities.

  36. (2018)  Hip-Hop Can Hack Everything!  Solutions from a Culture of Innovation  - Manny Faces
    • Hip-hop is a world-class disruptor.  It has transformed music, popular culture, fashion, business and advertising, creating (and upending) massive industries in its wake.  This talk explores the enormous innovative potential that hip-hop music and culture continue to exert across multiple fields and disciplines, including science and technology, education, health and wellness, politics and activism, journalism, the fine arts, and... well... everything.

  37. (2018)  History of the Maker Movement  - Limor "Ladyada" Fried, Sherry Huss, Mitch Altman, Phillip Torrone, and more
    • There are a few people who claim to be the "father of the maker movement."  This panel will explore the history of what is called the maker movement, and help un-erase some of the pioneers who have helped bring communities together, shared open-source, and built places for all hackers, makers, artists, and engineers.

  38. (2018)  Homebrew 68K Retrocomputing on Low-Cost FPGA Boards  - Keith Monahan
    • Growing up on the Commodore Amiga introduced Keith to the venerable Motorola 68000 processor.  This talk will share the technical details of how he integrated an open-source 68K soft-core processor on a $30 FPGA board: what challenges he faced, skills he needed to learn, and how he managed to create his own retrocomputer - complete with 7" touchscreen and old-school audio - from scratch.  This talk will touch on topics like computer architecture and design, Verilog HDL, 68K assembly language, electronics, and more!

  39. (2018)  How a Hackerspace Built a Legal FM Radio Station  - Saint, Hook, Pete Tridish
    • Montana Ethical Hackers (MEH) walks you through the trials and tribulations of developing KMEH 107.9 - End of the Dial Hacker Radio.  Their presentation ranges from overcoming low budget logistical challenges and the FCC application process to convincing the U.S. military to give up a call sign.  Content generation and copyright issues will be covered.  The talk will also include a quick background on the pirate radio movement of the 1990s, and how that spawned the legal LPFM service, which created thousands of legal LPFM stations.  You will learn about some of the practical challenges of starting radio stations, radio's role in today's media environment, and the future of community radio.

  40. (2018)  How to Pwn an Enterprise in 2018 (and 2019, and 2020...)  - Johnny Xmas
    • This talk will "reveal the magician's" secrets on all of the "low-hanging fruit" hackers used to compromise enterprises in 2018.  This will be a candid, detailed, step-by-step how-to attack chain walkthrough, explaining how and why the attacks work, and what steps can be taken to proactively defend against them.  Participants will walk away with highly actionable tasks to immediately take to work on Monday to not only bump their security posture up a distinctive notch with little to no hit on their budgets, but also inherently render future penetration tests more cost-effective by eliminating potential "cheap shots" that pen-testers love to take.  They will also, of course, walk away with the ability to become the domain admin of an average corporation from their couch in record time.

  41. (2018)  How Your Personal Information is Obtained and Exploited to Manipulate Your Emotions, Your Actions, and Your Vote  - Steve Rombom
    • Your habits, hobbies, friends, family, location (today, and for the past 17 years), activities, deepest thoughts, and desires are known, indexed, and analyzed.  Dataveillance is now all-encompassing and the "small window into your soul" is now a barn door.  Attack vectors now include photos, video, audio, self-installed wiretaps (i.e., Alexa) and an always-on ever-present tracking device (your cell phone).  Drink a certain type of cola?  You're 20 percent more likely to believe in space aliens.  Enjoy chunky peanut butter and own a cat?  You're significantly more likely to buy a Volkswagen.  Live in a certain ZIP Code?  Subscribe to a certain magazine?  Use a certain email domain?  Drink a certain kind of alcoholic beverage?  Order certain combinations of pizza toppings?  Drive a certain color car?  Visit certain noteworthy (for profilers) locations?  Data about these otherwise innocuous choices are now routinely merged and extrapolated into deep understanding of your personal characteristics and political beliefs, and are used to target you with information tailored to influence your emotions, actions, purchases and, especially, your vote.  This will be the HOPE talk Steven always wanted to give.  It will amaze, disturb, and frighten - and it will be Steven's last talk at any HOPE conference (he'll explain that, too).  Deprogramming available.

  42. (2018)  The Hype is Over, So What is Desktop 3D Printing Really About?  - Matt Griffin
    • While the world was falling in love with desktop 3D printers as a potential disruption to how consumer products might be created and manufactured (in the home), a parallel transformation was taking place that shows no sign of stopping.  It is time to cut through the bullshit and examine the revolution that actually took place!  Experience case studies and research that speaks practically to how manufacturing, medicine, design, and enterprise use of the technology is accelerating the evolution of product and hardware design, transforming how we manufacture and package products, and how HOPE audiences can leverage pipelines and strategies they have mastered for other purposes (web, IT, security) to move forward their design and hardware.  Welcome to the "data center moment" for fabrication technology!

  43. (2018)  I Dream of Game Genies and ZIP Files - Hacking the NES  - Vi Grey
    • The Nintendo Entertainment System existed in a time when video game consoles didn't have an operating system.  It was up to the game cartridges to tell the NES what to think and how to behave.  Cheating devices like the Game Genie worked by taking full advantage of that fact.  These cheating devices, along with the fact of cartridges being mightier than the console, opens up unusual and creative gameplay options that can be utilized by a game developer.  The design of these cartridges also allows for information to be discreetly concealed in unexpected ways.  Building on the research from his article in PoC||GTFO Issue 0x18 about concealing ZIP files in NES ROMS, Vi will share his process for creating a custom game cartridge that utilizes these unusual gameplay options while also making the cartridge data work as a fully functioning ZIP file and web page.

  44. (2018)  Inspiring the Next Next Generation of Hackers  - BiaSciLab, Kousei
    • Want to get started in the world of hacking but don't know how?  How do you inspire your kids to begin looking at things like a hacker?  When should you start?  What should you do?  Eleven-year-old old hacker BiaSciLab and 14-year-old Kousei will answer these questions and more as they set adults at ease with bringing their kids into the hacker world.  They will explain how they started their journeys, where they are planning to go, and how to get there.  This talk will also have lots of great tips for adults starting out too.

  45. (2018)  The Internet Society  - Joly MacFie
    • The Internet Society is an international, non-profit organization founded in 1992 to provide leadership in Internet-related standards, education, access, and policy.  Its mission is to promote the open development, evolution, and use of the Internet for the benefit of all people throughout the world.  Their efforts and skills are directly responsible for the streaming and archiving of The Circle of HOPE, so please help support their efforts and consider starting a chapter in your community.

  46. (2018)  Introduction to User Freedom  - Karen M. Sandler, Molly de Blanc
    • If you are coding, writing, or making art or any other creative works, at some point you need to pick a license for how you want to share what you've done.  A license represents a series of ethical, legal, and values decisions.  Instead of proprietary "software" and "culture," you have "free software" and "free culture."  The licenses used to accomplish this are the legal embodiment of a set of ideals represented in the four freedoms of free software.  This talk will provide a historical and philosophical overview of just what it means for something to be free, why it matters, and what your responsibilities are in a world where our experiences, our selves, and our lives have become intellectual property that may not always belong to us.

  47. (2018)  Is the Internet Sick?  Findings from Mozilla's Internet Health Report  - Jairus Khan
    • Our personal credit details have been stolen en masse.  Social media has been weaponized as a tool of cruel harassment.  The democratic process has been undermined by the manipulation of online news and ads.  We are beginning to see the health of the Internet as not just a technical issue, but a human one.  Mozilla's Internet Health Report is an open- source project that documents and explains how people worldwide are interacting with and affected by our connected world.  The report aims to provide a "big picture" of the global state of health of the Internet through the prism of five core issues: privacy and security, openness, digital inclusion, web literacy, and decentralization.  This talk will share findings from the 2018 Internet Health Report, and examine how we might use the concept of "Internet health" as a catalyst for change in our communities.

  48. (2018)  It Takes a Village to Hack a Voting System  - Matt Blaze, Harri Hursti, Margaret MacAlpine
    • Modern electronic voting systems are notoriously vulnerable to attack, and the 2016 election was perhaps the first time we saw evidence of state actors attempting to compromise local election system infrastructure.  But how insecure are the actual voting systems we use?  And how can the average hacker get access to these systems to find out firsthand?  Last year, the speakers organized the first ever Voting System Hacking Village at DEFCON, in which the community was invited to example, take apart, and hack several real voting systems used in U.S. elections.  Many exploitable vulnerabilities were discovered or reproduced over the course of the weekend.  This talk will describe how the voting village was organized, the technical and legal challenges in doing so, and how you too can (legally!) obtain and hack real election equipment.  The background and requirements for secure elections will also be discussed, as well as how technology can both hurt and help these requirements.

  49. (2018)  Lessons from an Undergraduate Course in Cybersecurity and Cyber Warfare - Is Our Children Securing?  - Ming Chow, Matthew Weinberg
    • This is the story of a course that was taught in the spring of 2017 at Tufts University.  It was taught jointly between the Department of Computer Science and the Department of Political Science and was created to develop bridges between students and faculty members in the fields of computer science, political science, and international relations.  The speakers will explain how the foundation of progress in cybersecurity can be achieved by addressing the knowledge and cultural gaps of technologists and policymakers at an early age.  This talk provides a prescription for running similar courses, including a list of topics covered, assignments, and outcomes.  It will also delve into the challenges encountered when the course was run, what was learned, students' comments, the growing need for such courses, and future opportunities.

  50. (2018)  Liberate Your E-book Reader with fread.ink!  - Marc Juul
    • fread.ink is an open-source operating system for electronic paper e-book readers based on the popular Debian GNU/Linux.  Why are these devices interesting and underutilized?  How have problematic laws like the DMCA impeded progress and what did it take to get a modern GNU/Linux system working on one of Amazon's devices?  This talk will attempt to answer these questions and show you how to start hacking your own paper display devices using fread.ink.

  51. (2018)  Life Before 1337: The Hacker's Illustrated Guide to Script Kiddie History  - John Dunlap, Alex Ivanov
    • For some, "script kiddie" is a term leveled at the younger, more boisterous, and less experienced members of the hacking community.  For others, it's a badge of honor confirming their dedication to the more inane, sardonic, and social aspects of the hacking scene.  In this talk, these two New York City security veterans will give a loving tour of the history of the script kiddie scene.  The speakers will describe the evolution of script kiddie staples such "1337" speak, ASCII art, widely shared premade exploits, hacking communities such as IRC/Usenet/forums, and a wide range of the cultural tropes born in the script kiddie scene.  The speakers' aim is to educate and entertain listeners by demonstrating the genesis of the hacker stereotype, and to fill in the blanks between media hyperbole and hacker culture reality.  Negative preconceptions about the hacker scene will be dispelled, and mistakes from hacker history will be explored.

  52. (2018)  The Locksport Variety Hour with TOOOL and Friends... Now with 100 Percent More Hour!  - Lady Merlin, Max, Click, Ann, Aidan , Nite 0wl, NoHackMe, TheSleep, Chaz, Spam, Smoke Legend, Deviant Ollam
    • Lockpicking has been an official part of the presentations at Hackers On Planet Earth for almost 20 years now.  (The Open Organisation Of Lockpickers (TOOOL) has existed for nearly two decades in the Netherlands and emerged here in the USA at The Fifth HOPE in 2004.)  And yet there are still so many stories to tell and new things to share!  This year's locksport panel will again include voices and faces from a wide range of picking groups around the country and around the world, but will incorporate more lessons and instruction than last time's free-for-all.  Everybody who asks a cool question will win a small prize.  If you ask a question that none of the panelists can answer, you win an even bigger prize.  If you bring an awesome demo device to show the panel and the crowd, you might win the biggest prize of all... audience members can offer up a lock or key of their own for inspection by the panel, who must endeavor to identify it and discuss how the mechanism works and how it might even be opened.

  53. (2018)  Mad (Data) Science - Teaching AI to Pop Boxes  - Kevin Hodges
    • In William Gibson's prophetic 1984 book Neuromancer, he described AI that could autonomously wage cyber warfare.  Today, we are regularly warned about the security and privacy implications of software that can learn and make decisions from massive datasets, but rarely do we discuss the possibility of this same software being used to make cyber attacks, or the possibility that it could escape our control.  Through a series of questionable ethical decisions, the first iteration of just that has been developed.  WinterMute is an open-source deep learning project that can assess and exploit a network, reproduce itself, pivot on a compromised machine, and learn from each step.

  54. (2018)  Making Sense of the Ether  - Marc DaCosta
    • The airwaves can be a cacophonous place.  Signals from GPS satellites exist alongside Bluetooth headsets and the dispatch channels of police stations.  The emergence of low-cost Software-Defined Radios (SDRs) have made this world more accessible than ever.  In this talk, Marc will discuss how public data can be joined with the electromagnetic spectrum to better understand the world around us.  In the first portion of the talk, he will discuss how governments regulate the usage and ownership of the electromagnetic spectrum.  The data residue of this process can be used for everything from geolocating electronic border surveillance infrastructure to discovering the location and transmission frequency of every McDonald's drive-thru radio.  He will also discuss how various protocols for data transmission can be decoded and joined with contextual public data.  For instance, every cargo ship emits an "automated identification system" signal that can be joined with shipping records to understand what the ship is carrying.  Attendees will leave with a richer sense of how the radio waves are being used and the tools necessary to critically explore them further.

  55. (2018)  Mixing DTMF Tones in Space, Illuminating the Aurora with Giant Cat Pics, and Other True Stories About HAARP  - Chris Fallen
    • Internet theories abound that the High-frequency Active Auroral Research Program (HAARP) ionospheric research facility in Alaska is used for sensational and nefarious purposes such as conducting mass mind control, triggering earthquakes, causing hurricanes, spraying chemtrails, and even making local caribou walk backward in circles.  Peer-reviewed journal papers postulate that scientists use the HAARP transmitter to conduct ionosphere radio modification experiments including enhanced airglow (i.e., "fake aurora"), artificial magnetic field-aligned irregularities, stimulated electromagnetic emissions, plasma wave instabilities resulting from electromagnetic pump wave decay, cross modulation effects, and ELF/VLF radio wave generation.  This talk will explore recent experiments, including the first modern recreation of the Luxembourg effect which featured DTMF tones and musical compositions written to take advantage of cross modulation, the first crowd-funded HAARP experiment, and the first SSTV image broadcast simultaneously with transmissions that also created fake aurora.  Additionally, the HAARP facility and the software that runs the main HF transmitter will be discussed, as will small elements of truth to some of the conspiracy theories.  Finally, this talk will suggest how you can participate in future experiments.

  56. (2018)  Movie: Glossary of Broken Dreams  - Johannes Grenzfurthner
    • Puppets!  Pixels!  Anime!  Live action!  Stock footage!  Johannes gives an ideotaining cinematic revue about important political concepts.  Everyone is talking about freedom!  Privacy!  Identity!  Resistance!  The Market!  The Left!  But, yikes, Johannes can't tolerate ignorant and topically abusive comments on the "Internet" anymore!  Supported by writer Ishan Raval, Johannes explains, reevaluates, and sometimes sacrifices political golden calves of discourse.  A must-see for politically interested hackers.  Not to be used with false consciousness or silicone-based lubricant.  A film paved with good intentions.
    • Glossary of Broken Dreams - Trailer
    • Glossary of Broken Dreams  Watch online for free.

  57. (2018)  Networked Authoritarianism  - Nathalie Maréchal
    • Nearly two years into the Trump administration, it's practically a cliche of Twitter gallows humor to quip that the day's bonkers headlines are the result of a Marvel-esque plot twist that has transported us into a parallel universe.  But of course, powerful forces have been laying the groundwork for a long time.  Networked authoritarianism is a political system that leverages Information and Communications Technologies (ICTs) and media regulation to carefully control the expression of dissent in a way that gives the impression of limited freedom of expression without allowing dissent to gain traction.  Networked authoritarianism combines strategies and tactics from the surveillance capitalism of Silicon Valley and from the information controls practiced by illiberal regimes around the world to create strategic infrastructures to control information flows domestically and to intervene in global media systems.  The democratic regression and rise of ethno-nationalism around the world is directly linked to networked authoritarianism.  How did we get to this point, and how do we fight back?

  58. (2018)  New Cryptography  - George Tankersley, Filippo Valsorda
    • Cryptography is usually associated with encrypting and signing messages, but since the 1990s, the field developed new tools that bring completely new capabilities: from PAKE protocols that make brute-forcing passwords impossible, to zero-knowledge proofs enabling blind credentials.  This talk will take a look at all those things modern cryptography can do beyond the old encryption and signatures.

  59. (2018)  NotPetya: Ransomware vs. Cyber Action  - Roel Schouwenberg
    • The NotPetya "ransomware" made the headlines last summer because it spread widely and hit major logistics supply chain companies.  It caused $10 billion in overall damages.  This presentation will dissect the technical, disinformation, and influence operation components of this extremely effective and misunderstood campaign.

  60. (2018)  The Onion Report  - David Goulet, Alison Macrina, Steph Whited, Matthew Finkel
    • The Tor Project has been hard at work building usable free software to fight surveillance and censorship across the globe.  Join a handful of Tor contributors at this panel and learn all about the state of the onion and what Tor has been up to since the last HOPE.  They'll talk about adding new security features, improving Tor Browser on Android, deploying the next generation of onion services, making Tor more usable, lowering the network overhead, making Tor more maintainable, and growing the Tor community with new outreach initiatives.  They'll also share some of what you can expect from Tor in the coming year, and will leave lots of time for questions from the community.

  61. (2018)  Online Monitoring of the Alt-Right  - Caroline Sinders, Freddy Martinez
    • Online communities have become a popular recruitment platform for alt-right and other extremist groups.  While there is no standard playbook for alt-right recruitment, some major themes emerge, including recruiting on Discord servers, Reddit boards, Chan boards, and other platforms.  Effectively, there is a web of overlap linking these disparate sites under the umbrella of the larger alt-right ideology and ethos.  This talk is part how-to and part explanatory on research conducted by the speakers.  It will cover some of the technical and ethnographic methods that are being used by researchers, activists, journalists, and others to monitor the evolving ecosystem, ideologies, tools, and tactics of the alt-right.  The discussion will include some of the tooling that developed to monitor the alt-right and their online communities: both online and off.  Also included will be coverage of the analysis that was performed alongside Unicorn Riot on analyzing thousands of leaked Discourse chats, as well as a dictionary of alt-right terms and memes that Caroline has been assembling from her research.  Finally, the talk will focus on future concerns for the Internet, including safety, censorship, etc.

  62. (2018)  OpenOversight: XKEYSCORE for Cops - Tracking and Surveilling Your Local Police Department  - Jennifer Helsby, Camille Fassett
    • Through highly sophisticated surveillance technology from drones and license plate readers to facial recognition, law enforcement agencies have sweeping and unprecedented abilities to compile databases of the people.  But despite these capabilities and the prevalence of police abuse of power, the public is largely left in the dark about law enforcement and their activities.  In this political context, it's on the people to hold police accountable, and surveillance technology and data collection are methods that should not be unilaterally in the hands of law enforcement.  OpenOversight is a project developed by data liberation collective Lucy Parsons Labs that consolidates police information from public records, public submissions, and web scraping into an open- source, community governed database.  In this session, Jennifer and Camille will discuss how it works, how you can bring it to your city, and what's next.
    • Green Bay Employs Retarded Police (GERP)

  63. (2018)  Owning NFC Toys I Own: A Case Study  - Vitorio Miliano
    • NFC toys are figurines with a built-in near-field communication tag, containing supporting data for games or play.  Reading from and writing to these figures is restricted; you can buy the toy, but only special hardware or software can fully use it, not you!  This introductory-level case study will explore the NFC tags found in three makes of toys, using off-the-shelf hardware and software.  You'll see how much can be learned with each different tool, and once read/write credentials are obtained, what some of the legal risks are under the DMCA.  Original documentation and code will be presented to generate credentials for any of the three makes of NFC toys, and NFC toys will be distributed for attendees to explore on their own.

  64. (2018)  The Phone System Is Dead - Long Live The Phone System!  - TProphet
    • At the dawn of the modern era of telecommunications, the underlying SS7 protocol was a marvel of modern engineering.  For decades, it was the technology underneath almost every phone call, routing conversations securely and efficiently across the planet.  And then, almost overnight, everything changed.  The Internet converged with the phone system.  This happened very fast and caused serious problems.  These days, SS7 is the bane of every telecommunications engineer's existence and is often the root cause of poor telecom security.  In this talk, TProphet will take you around the world and across the telecommunications landscape to explore the past, present, and - hopefully - future of the phone system.

  65. (2018)  Phonopticon: Leveraging Low Rent Mobile Ad Services to Achieve State Actor Level Mass Surveillance on a Shoestring Budget  - Mark Milhouse (amne51ac)
    • By now, we all know that mobile advertisements aren't secure.  How would an attacker take advantage of that, though, and spy on people without their consent, knowledge, or interaction?  And how do we defend against that?  This talk will be a journey through the demand-side of advertising as we put ourselves in the role of an attacker, build an ad-based surveillance system, and unleash it on the masses.  Mark will demonstrate how, using the built-in features of advertising Demand-Side Platforms (DSPs), it's easy to build a surveillance system that can track unsuspecting people.  He'll demonstrate that some platforms make it much easier than it needs to be, and show that there's more than just geolocations at risk here.  Finally, Mark will discuss some ways that everyone can help mitigate this, from the users all the way up to the ad networks and software developers.  Like every good spy story, this one includes Russian ad networks, hastily written code, and GPS coordinates - lots of GPS coordinates.  By now, if you're still clinging desperately to the hope that your location is safe, then this talk is for you!

  66. (2018)  The Problem With The Hacker Mystique  - Gillian "Gus" Andrews
    • There are common themes in the stories of those of us who have grown up in hacker communities.  We show up as teenagers, excited by the sexiness, the secrecy, the possibility of meeting the legends who performed powerful spells of tech - or working those spells ourselves.  Maybe working at the edge of the law.  Maybe we'll even change the laws as we hack.  As we get older, digital security takes on different roles in our stories.  For some of us, it remains a fun thing to do with friends.  For others, it's a political cause.  For some, it's the meat and potatoes of our jobs.  And for others, digital security has become very, very unsafe.  Or it was always unsafe, and the dangerous storylines are just now becoming clear.  This talk will discuss components of hacking and security - technical expertise, secrecy, illegality, idiosyncrasy, and trust - that contributed to a mystique which until recently hid years of abuse by a number of hacking "rock stars."  Gus will explore the psychological and institutional reasons why our communities let them keep acting that way, and ask some hard questions: are there aspects of hacking and infosec which make abusive experts difficult to avoid?  What parts of the hacker mystique will we need to give up in order to make our community resistant to being trashed like rock stars' hotel rooms?

  67. (2018)  Programming 1980s LEGO Robotics  - Evan Koblentz
    • Everyone knows about LEGO's present-day Mindstorms robotics system.  It is very popular, eminently hackable, and quite expensive.  But virtually nobody knows that Lego also produced a robotics kit in the 1980s!  It was only sold to schools and few ever bought it.  Programs were developed on your choice of an Apple II or an IBM PC, using languages such as BASIC, LOGO, or assembly.  Although the programming techniques are vintage, not modern, they're easy to understand.  Evan will show several examples, explain how it all works and why it works, and will teach how anyone can obtain or replicate the 1980s kit for their own modern fun at home.

  68. (2018)  Protecting Whistleblowers: An In-Depth Look Within GlobaLeaks Platform  - Michael Casadevall
    • Ask yourself: Have you ever thought about what it takes to protect a whistleblower?  In the world of whistleblowing, as counterintuitive as it seems, it's frequently required that the whistleblowers must personally identify themselves and document their knowledge.  To protect against reprisals, not only must a whistleblower secure their identity, but a receiving organization must secure their information.  To help resolve these issues, the GlobaLeaks platform is designed from the ground up to tackle problems in secure whistleblowing by providing a simple turnkey system that even non-technical users can successfully deploy and operate.  This talk will look under the hood of GlobaLeaks, a free and open-source whistleblowing solution, and see how they work to protect sensitive information about whistleblowers.

  69. (2018)  Qubes OS: The Operating System That Can Protect You Even If You Get Hacked  - Michah Lee
    • "If you're serious about security, Qubes OS is the best OS available today," says NSA whistleblower Edward Snowden.  "It's what I use, and free."  In most operating systems like Windows, macOS, and all Linux distributions, all it takes is one mistake - open the wrong PDF, plug in the wrong USB stick, "curl | bash" the wrong URL - and it's game over.  Even without root, the attacker can access all of your data, take screenshots, listen through your mic, watch you through your webcam, and get persistence to spy on you in the future.  Qubes OS aims to be a reasonably secure operating system that doesn't have this problem.  In Qubes OS, your host machine runs a thin layer of software for managing a graphical desktop environment and all other software is compartmentalized in separate virtual machines, with strict controls on what hardware they can access and how they can communicate, all while being usable enough to run as your daily OS.  In this talk, Micah will show off some of the cool things that this approach makes possible, like opening email attachments in "disposable VMs," managing anonymous identities, keeping secrets like password databases, PGP keys, and sensitive documents stored in vaults without Internet access, and much more.  Beginners are welcome.

  70. (2018)  Radio Statler!  A Decade of Doing it Live!  - Beaches, Nikgod, TechDarko, Bunni3Burn, Johnny Xmas, Nite 0wl, Sidepocket, Stoppay, xio
    • Since 2008, Radio Statler! has been broadcasting original content from HOPE to the rest of the world.  Content has included interviews with speakers, extended Q&As, panels, interesting people found in the hallways, and the occasional glimpse into the things that happen outside the talk rooms.  Join this panel as they definitely stay on topic and tell the how and why of Radio Statler!, the challenges of setting up a temporary online radio station, and lots of stories!

  71. (2018)  Reverse Engineering a Portable USB Firewall Appliance and Its Hardware Improved Recreation  - Dernyn
    • In this talk, penetration/reverse engineering techniques of both hardware and software will be demonstrated by breaking into a portable "secure" Linux-based firewall device's firmware, which will then be recreated and improved with a Linux single board computer.  The original device provides anti-virus, anti-spam, anti-spyware, intrusion detection and prevention, VPN client and website filtering, and parental control - and it all runs on a computer the size of a pack of gum.  Dernyn will provide a step-by-step tutorial on how to gain full access to the inner workings of this discrete dedicated Linux-based ARM mini-computer firewall appliance.  There will be a full analysis of its inner workings, with a dissection of the electronics and implemented system and software infrastructure, networking/firewall policies, and an overall security level analysis focusing on the lack of protection/security which the manufacturer claimed as Pentagon level protection.

  72. (2018)  The Right to Repair Panel  - Nathan Proctor, Gay Gordon-Byrne, Kyle Wiens
    • It's time we restored ownership rights in a digital world, and that begins with letting us fix our electronics.  As companies work to monopolize repair, use copyright law to block access to what we need to fix things, and design products that cannot be repaired, leaders from Right to Repair will share stories on how people are pushing back.  They will give a presentation on the current state of Right to Repair legislation across the country and concurrent efforts with the U.S. Copyright Office Section 1201 exemptions to the DMCA.  The discussion will include legal principles behind Right to Repair, including antitrust, contract law, warranty law, and how EULA and the DMCA have been weaponized to remove key intrinsic rights of ownership.

  73. (2018)  Scientific and Amateur Analysis of the Facebook Algorithm  - Claudio Agosti
    • The algorithm gives a personalized experience to each of us: the only way to understand its agenda, priorities, and values is through collective observation.  With the facebook.tracking.exposed project, Claudio did some black box testing of the Facebook algorithm.  It can be replicated by other researchers or among your group of friends.  Spoiler:  There is no algorithm neutrality; every user should be in control of their algorithm.

  74. (2018)  Securing the Delivery of Email  - *Sydney Li
    • In early 2014, research revealed the horrible state of email over TLS.  About half of email was sent in plaintext and, for the email sent over TLS, half of those servers presented certificates that were invalid or self-signed.  On top of this, some governments and ISPs were regularly downgrading SMTP connections to plaintext.  Since then, there have been multiple efforts by IETF and large mail server operators to secure the delivery of email.  This talk will summarize the state of secure email delivery in 2018 and discuss ongoing initiatives and efforts to protect against MitM and downgrade attacks, including MTA-STS, DANE, and STARTTLS Everywhere.

  75. (2018)  Sensors Everywhere!  What's Available, How They Work, and How You Can Use Them  - Jonathan Foote
    • From the IR sensor in the bathroom to the face detector in your phone, sensors are everywhere.  Jonathan will give a guided introduction to the vast zoo of electronic sensors available.  From commonplace accelerometers to sensitive pulse oxygen meters, come learn about a wide variety of sensors, how they work, and how you can use (or hack) them.  He will cover sensors from the commonplace to the exotic: optical sensors including affordable lidar, UV, and passive IR; magnetic and inductive sensors; MEMS pressure gauges and microphones; position and location detection; force, flex and strain gauges; temperature sensors and thermistors; and a variety of health and biosensors.  Though this talk is at the level an electronics hobbyist will enjoy, even experts will likely find something they haven't seen before.

  76. (2018)  The Sex Geek Returns: Hacking Plus Human Sexuality AMA  - Kit Stubbs
    • Got a burning question about sex?  Curious about making your own silicone sex toys?  Not sure of the difference between "biological sex" and gender?  Wonder how you might start hacking a store-bought sex toy?  In this session, Kit presents "I'm A Queer, Non-Binary, Disabled Trans Femme Originally From Missouri Who Makes Their Own Geeky Sex Toys And Runs A Sex-Positive Nonprofit: Ask Me Anything Join Kit "where did this b!tch get [their] doctorate" Stubbs for their very first AMA!  It'll start with a quick survey of topics to get your ideas flowing, including sex and gender, technological empowerment for sexuality and pleasure, and DIY toys.  Then the floor will be opened for your questions.  Whether you're ready to ask a question or just happy to listen, join this celebration of hacking and human sexuality!

  77. (2018)  Sex Worker Rights and Internet Freedom  - Maggie Mayhem
    • Digital media and communications technologies have been a critical component in improving the working conditions, health, and safety of sex workers in many ways.  Message boards and thriving social media communities created strong communication networks where lifesaving information such as bad dates could be disseminated among peer networks to protect those in the sex trade from harm and find supportive allies.  In recent years, sex worker rights have been systematically eroded in the name of combating human trafficking, despite a lack of evidence to justify these actions and the fallout they cause.  The recent passage of the Stop Enabling Sex Traffickers Act (SESTA) not only continues this dangerous trend, it places human trafficking victims at greater risk and jeopardizes Internet freedom for all by eliminating Section 230 of the Communications Decency Act.  With online platforms open to civil and criminal liability for third-party content, it is inevitable that mass censorship will follow and marginalized voices will face the steepest penalties.

  78. (2018)  Snowden's Critical F*ckin' Flaw  - Johannes Grenzfurthner
    • Back in the good old days of 2015, Shami Chakrabarti wrote an opinion piece for The Guardian, stating that Edward Snowden "is a hero."  She claimed that saying so didn't make her an apologist for terror; it made her a firm believer in democracy and the rule of law.  Many saw and still see it this way.  Snowden, the true protector of freedom!  It's heard frequently in hacker circles, echoing like a prayer in a church.  He's a freedom fighter, standing for the American ideal, codified in the Constitution.  The state apparatus, not Snowden, deserves our disgust and derision.  Johannes thinks a fatal misconception is going on, and that we have to talk about it because way too many people step on this ideological turd.  He will try to explain what the fallacy is and use a lot of curse words doing so.

  79. (2018)  Social Engineering  - Evil Corley and Friends
    • One of HOPE's longest running traditions, this panel is a fun gathering where stories of social engineering triumphs and failures are shared.  Social engineering is, of course, the subsection of hacking that focuses on obtaining information out of people by gaining their trust and lying through your teeth.  As long as there's a human somewhere in the equation, this method of compromising security will always be possible.  Techniques will be shared and an experiment or two will be performed live over our trusty landline.

  80. (2018)  SpellCheck: The Hacker Spelling Bee  - Brianne Hughes
    • English is a messy language, and no amount of spellcheck can stop you from writing about "security breeches" or "rouge towers."  Come witness your peers bravely seek the redemption they've hoped for since elementary school as they battle through increasingly difficult security terms for fun and a moderate prize.  The bee will warm up with "asset" and "bypass" and work its way up to rounds where capitalization will count and determine the winner.  The wordlist is based off of the most recent version of the Cybersecurity Style Guide atbit.ly/securitywords.  Twenty spellers total will participate.  You can sign up in advance at the Info Desk during the conference.  A complete list of rules for the SpellCheck bee will be available there.

  81. (2018)  Spotlight on SecureDrop: Anonymous Whistleblowing in the Trump Era  - Jennifer Helsby
    • The SecureDrop anonymous whistleblowing platform has become the journalism industry standard for communicating with anonymous sources and accepting high security leaks.  The system was co-created by the late Aaron Swartz and first announced at HOPE four years ago.  Each SecureDrop instance is physically hosted inside a news organization, and sources communicate with journalists by accessing a web application available over a Tor onion service.  In the past two years, adoption has increased to include most major new organizations, including The Associated Press, USA Today, and The Wall Street Journal.  This talk will cover the challenges SecureDrop administrators, journalists, and sources are facing, how SecureDrop has been scaled to more organizations, and progress in developing new tools for journalists to work with leaked documents, including a Qubes OS-based workstation.  In the Trump era - during which the Department of Justice has issued a crackdown on whistleblowing in response to the current epidemic of leaks from the White House - secure communication tools like SecureDrop are more iimportant than ever before.
    • WarOnWhistleBlowers.com
    • Official Trailer
    • Oliver Stone Announcement
    • Preview #1

  82. (2018)  Surveillance Architecture: 21st Century Surveillance and the Tools to Fight Back  - simplymathematics
    • In the last decade, we've learned a lot about the ways in which state surveillance is conducted - the state has likewise hardened their approach.  This talk will examine solutions to this mass surveillance in the context of community-controlled infrastructure.  In particular, the roles that encrypted messaging, distributed file systems, and mesh networking play in fighting back against the ever encroaching Skynet will be examined.

  83. (2018)  Surveillance Psychiatry and the Mad Underground  - Jonah Bossewitch
    • Surveillance psychiatry is an emerging practice which seeks to predict and prevent mental illness across a broad population by using algorithms and big data.  A new generation of digital systems for policing normal are currently in beta and will soon enable authorities to control all modes of social deviance and protest.  Electronic health records, data mining social networks, and even algorithmically classifying video surveillance will significantly amplify this approach.  Researchers are claiming they can diagnose depression based on the color and saturation of photos in your Instagram feed - and predict manic episodes based on your Facebook status updates.  Corporations and governments are salivating at the prospect of identifying vulnerability and dissent.  Although they will carefully use the language of suicide and violence prevention, these lines are not so clear.  When algorithms are scrutinizing our tweets to determine who is crazy, it will become increasingly difficult to avoid a diagnosis.  But there is hope.  In this millennium, a new wave of mad resistance has emerged - the Mad Underground, a thriving network of mental health activists who are developing innovative strategies for resisting psychiatric domination and creating new models of community driven emotional support.  By listening to their voices and understanding their visions, we can diffuse the menacing time bomb of big data surveillance psychiatry before it explodes, putting the depths of our emotions in the realm of public consumption and subjecting us to new forms of oppression.

  84. (2018)  Tech Warrior Camp at Standing Rock: Lessons for Keeping the Lights On and the Livefeeds Streaming  - Lisha Sterling
    • In 2016 and early 2017, tens of thousands of people gathered in camps on land near and on the Standing Rock Sioux Reservation in an attempt to stop the construction of the Dakota Access Pipeline.  At one point, the camps made up the third largest "city" in North Dakota, and yet there was no mains electricity, telephone service, or plumbing.  Law enforcement and private security used continuous "low intensity warfare" tactics on this temporary community on the plains.  The Tech Warrior Camp, led by Geeks Without Bounds, built and maintained a wireless ISP for the camp, as well as providing other technical support for communications and digital security.  They did this despite 60 plus mph winds and -20F temperatures.  In this talk, you can hear about some of the lessons gained from that experience, along with models for building community ISPs that are resilient to both human adversaries and natural events.

  85. (2018)  Torrent More Pharmaceutical Drugs: File Sharing Still Saves Lives  - Michael Laufer
    • Two years ago, the Four Thieves Vinegar Collective became public at The Eleventh HOPE after almost a decade of working underground, and debuted the first generation of the Apothecary Microlab, the open-source automated chemical reactor designed to synthesize the active ingredients of pharmaceutical drugs.  They synthesized Daraprim onstage, and called Martin Shkreli's cell phone from stage.  It was a good time.  Since then, the reactor has developed, and been involved in more complicated syntheses, and hacking medical hardware.  Most notably, they released plans for a DIY version of the EpiPen (the EpiPencil) that anyone can make for $30 US.  Come see the new releases they have planned, as well as the new beta unit.  Learn how to make medicine from poison, how to use the shrouding of information about medicine to make custom-tailored treatment programs for rare diseases, and how to use public data to find new, more efficient synthesis pathways for drugs.  Hack your health.  We can torrent medicine.  File sharing saves lives.

  86. (2018)  Tor: The Dark Arts of Attack and Defense  - EOF (Hunter Rogers)
    • This talk discusses modern practical attacks on the Tor anonymity network.  The topics include penetrating Tor hidden services and infrastructure, as well as open-source intelligence, operational security, social engineering, and client side exploitation as they relate to the Tor network.  Real-world examples are examined, and methods of self-defense are explored.  This discussion will arm the audience with the knowledge they will need to engineer attack-resilient anonymous ecosystems, and to defend their liberty, their lives, and their human rights of privacy, anonymity, and free speech in an age of ubiquitous surveillance.

  87. (2018)  Tracing Invisible Neighborhoods: The Brooklyn Pirate Radio Sound Map  - David Goren
    • Every day in Brooklyn, over 30 unlicensed radio stations fire up their transmitters and take to the air.  Historically known as pirates, they crowd onto an already packed FM dial, beaming transgressive culture- bearing signals into West Indian, orthodox jewish, and Latino neighborhoods.  The sound map project seeks to explore and understand the forces that drive these stations, the conditions they operate under, the needs of their audiences, and their effect on licensed stations.  The Brooklyn Pirate Radio Sound Map (BPRSM) is an interactive archival home for intensely local, neighborhood focused radio programming.

  88. (2018)  Trolling, Free Speech, and the Hacking of Our Media/Attention Landscape  - Matt Goerzen, Joan Donovan, Jeanna Matthews
    • Trolls are attention hackers, using social and technical means to bait journalists, set agendas, game media gatekeepers, and direct audiences.  This panel of members of the media manipulation team at Data & Society will consider the relationship between trolling and hacking, free speech, and the implications for our media/attention landscape.  Matt will focus on hackers who have used trolling techniques to disclose vulnerabilities and elicit public pressure.  Joan will talk about source hacking techniques, a tactic where groups coordinate to feed false information to journalists and experts, often during times of crisis.  Jeanna will discuss the relationship between free speech, amplification of speech through platform and media manipulation, and the implication of possible interventions.  The floor will be open to comments, questions, and a discussion which hopefully will continue beyond the session itself.

  89. (2018)  Trolling the Trolls and the Trolls That Troll Them  - Da Beave, Faux Real
    • It has been said that Twitter bots and trolls helped Russia influence the United States 2016 presidential election.  Looking towards the 2018 midterm elections, many voters, politicians, and government agencies are anxious and uncertain of what may come: "How might another nation influence our election?" "Might the potential for electoral interference persuade some politicians to preemptively 'get on board' with those who may influence the political outcomes?" The torrent of news broadcasts and research publications on the subjects of social media manipulation have led to greater confusion in some respects.  This talk covers aggressive research conducted over the last year focusing on bots, fake news, and hate speech on Twitter.  This "aggressive research" uses methods and techniques that are directly at odds with the Twitter ToS.  To best understand the motives and techniques of your adversary, it's sometimes best to walk their shoes.  Using and abusing Twitter API, using automation to engage suspicious accounts without using the API, and engaging in "nontraditional" data collection methods (i.e., "social engineering"), 'Da Beave' and 'Faux Real' have been collecting and analyzing a wide range of data related to their targets.  The methods employed have enabled them to gain a wider perspective than any amount of social media data alone could provide, and these techniques have allowed them to bring some of the "trolls" and "bots" out of the dark and into the daylight.  This talk covers what they did and how they did it.  Source code will be released as an open-source project (GPLv2).

  90. (2018)  Updates on I-Star Organizations from the Bullshit Police  - Amelia Andersdotter, Mehwish Ansari, Avri Doria, Mallory Knodel
    • A panel of experts, technologists, and lawyers will give an update on several I-star organizations, namely ICANN, IETF, IEEE, and ITU.  Short presentations will touch on the major controversies in each space as they relate to human rights, namely freedom of expression and the right to privacy.  Questions to the panel from the moderator will draw out the tensions and synergies of human rights considerations in Internet governance and standards setting across the I-star bodies.  Questions from the audience are encouraged.

  91. (2018)  U.S. and E.U. Legal Updates: Privacy, Security, and Liability  - Alex Muentz
    • We're seeing a lot of changes in privacy law and security regulations in both the European Union and the United States.  Some of these are beneficial, while others may make us less safe and free.  Alex will discuss the current state of GDPR (the E.U.'s General Data Protection Regulation), recent U.S. SEC guidance on reporting security breaches, as well as the recently passed FOSTA-SESTA.  Of course, hypotheticals and Q&A will follow.

  92. (2018)  The U.S. Press Freedom Tracker: Documenting Attacks on the Press in the Age of Trump  - Alexandra Ellerbeck, Camille Fassett
    • Last August, a coalition of more than two dozen organizations dedicated to press freedom came together to launch the U.S. Press Freedom Tracker, a website that systematically documents press freedom violations in the United States.  When the tracker was launched, it was never anticipated that more than 100 cases would be logged in the first year.  These cases show that Trump's heated rhetoric in D.C. is far from the only press freedom story.  Instead, journalists face obstacles in courtrooms, city halls, and protests.  Information from the tracker has already identified concerning patterns, such as the fact that two-thirds of journalists arrested in 2017 were caught up when police used a controversial tactic known as "kettling."  It still remains to be seen how much of Trump's legal threats to journalists are bluster, but the press freedom tracker is rigorously documenting them, along with the myriad of other threats that often go overlooked.

  93. (2018)  We Must Legislate to Block Collection of Personal Data  - Richard Stallman
    • With surveillance so pervasive, weak measures can only nibble around the edges.  To restore privacy, we need strong measures.  Companies are so adept at manufacturing users' consent that the requirement hardly hampers their surveillance.  This talk will discuss how what we need nowadays is to put strict limits on what data systems can collect.

  94. (2018)  What Should Go into a dotMOBI Website?  - The Cheshire Catalyst
    • The dotMOBI TLD (top-level domain) has been established for websites meant to be read on Mobile devices (mobile phones and tablets).  The Cheshire Catalyst (Richard Cheshire) will describe his thoughts on what design elements are needed to go into such a website for usablity on not just the latest smartphones, but on older Feature Phones as well (ask Nokia how their new 3310 is doing).  The web site H12.Mobi will be used as an example.

  95. (2018)  Why Trade Secret Law Can't Stop Hackers  - Ed Ryan
    • Patent law can't cover everything.  In cases where the publicity of a patent is too high a price to pay, the law provides protections against the "misappropriation" of trade secrets, which have no expiration date.  Trade secret law has been strengthened in recent years to include federal protection and warrantless seizure of property.  This talk introduces the trade secret and industrial espionage laws and outlines the limitations of these laws in the face of a person intent on liberating closely held secrets.  It will cover the Defense of Trade Secrets Act of 2016, including the provisions for "ex parte seizure" of property.  This talk is an academic discussion of trade secret law and should not be construed as legal advice.

  96. (2018)  Your Blockchain Sucks  - Glenn Willen
    • It sure seems like everybody wants a blockchain these days, doesn't it?  It started with finance, but now we have blockchain for books, airlines, advertising, clinical trials, energy... and that's just the first two pages of Google hits.  But why does everybody want a blockchain?  There's a ton of a lot of blockchain hype right now, and frankly, 95 percent of proposed blockchain projects are crap.  So what precisely is a blockchain, and why is it useful?  Where did it come from, what is it good for, and - more importantly - what is it totally garbage at?  And what kinds of bullshit are people trying to use it for that just doesn't make any goddamned sense?  Glenn is here to tell you exactly why your blockchain sucks.

  97. (2018)  Your IoT Roommate and You - Living with the Enemy  - Michael "Sveder" Sverdlin
    • More and more people, hackers included, are allowing IoT devices into their homes, while simultaneously not a week goes by without a new IoT botnet or an attack on and involving IoT devices.  Time to talk about what the paranoid of us already know - how to live with your IoT roommates and keep your privacy, security, and sanity.  Michael will go through the story of his smart water heater and how he's slowly but surely making it more hacker friendly - from replacing its permission hungry app, to inspecting the software and the remote API it insecurely communicates with, and finally physically taking it apart in order to make sure it doesn't have added "features."  The talk will include technical details about his device, but more importantly it will contain strategies and ownership tips that will work on any other.  IoT devices are moving in - will you be prepared?

  98. (2018)  Closing Ceremonies  - Evil Corley
    • Too many people make the mistake of leaving before we get to the end.  And in the case of HOPE conferences, that end is a bit later than most other conferences.  We believe that the day after a HOPE conference is a lost day, a time of recovery, perhaps even a holiday.  Therefore, it makes little sense to not enjoy to the fullest this Sunday evening where we all celebrate another fun weekend together and start planning for the next one.



HOPE 2020





  1. (2020)  In the Beginning  - Evil Corley
    • A look at what's ahead as HOPE 2020 begins...

  2. (2020)  2020 Elections: What to Expect  - Harri Hursti
    • 2020 will be a consequential year of elections for many nations, but one of the most followed will be the United States.  USA primaries have foreshadowed potential issues to come in the November elections.  Even before China COVID-19, the trial of new technology threw caucuses and primaries into the center of the controversy.  With the coronavirus, the national debate about the security of mail-in voting has ignited.  What are the facts and expectations of major differences from a security point of view in 2020 vs. prior elections like 2018 and 2016?

  3. (2020)  75,000 FOIA Requests Can't Be Wrong: Lessons From a Decade of Transparency Spelunking  - Michael Morisy
    • Over the past ten years, transparency non-profit MuckRock has helped thousands of requesters file tens of thousands of public records and Freedom of Information Act requests to government agencies large and small.  In the process, they've unveiled everything from the government's program giving local schools grenade launchers brought back from war zones to the CIA's declassified board game collection.  Join Michael on this walk through the government's fascinating hidden archives and learn the secrets of what actually works when it comes time to convincing agencies to give up some of their most closely held secrets.  Throughout the conference, he'll also be helping conference attendees workshop their request ideas, and during the presentation the best ideas will be revealed with prizes for winning submissions and inspiration for everyone else.

  4. (2020)  A Death Blow to the Web of Trust  - aestetix
    • The PGP web of trust is broken.  Actually, that's not quite right.  "Broken" implies it was working at one point, and web of trust never really worked.  But that won't stop us from having fun with it.
    • This talk will look at PGP at the protocol level, show some really glaring issues with how the web of trust was designed, and some really fantastic ways that it fails.  It will also introduce a series of tools that can help you to wreak havoc on the keyservers.

  5. (2020)  A Decepticon and Autobot Walk Into a Bar: A New Python Tool for Enhanced OPSEC  - Joe Gray
    • When we see the terms "Natural Language Processing" (NLP) or "Machine Learning" (ML), often our guts are correct, and it is vendor marketing material, frequently containing FUD.  After tinkering with various libraries in Python and R with the use of some OSINT and SOCMINT techniques, Joe has found a use for NLP and ML that is 100 percent FUD-free in the form of a brand new Python-based tool.
    • In this presentation, Joe addresses topics that he has frequently spoken about in past years: disinformation, deception, OSINT, and OPSEC.  When working through learning NLP and ML in Python, it dawned on him: marry these technologies with Decepticon for good.  Enter the Decepticon bot.
    • The Decepticon bot is a Python-based tool that connects to social media via APIs to read posts/tweets to determine patterns of posting intervals and content, then takes over to autonomously post for the user.  What is the application, you ask?  People who are trying to enhance their OPSEC and abandon social media accounts that have been targeted without setting off alarms to their adversaries.  Use case scenarios include public figures, executives, and, most importantly, domestic violence and trafficking victims.

  6. (2020)  Advanced Wi-Fi Hacking With $5 Microcontrollers  - Kody Kinzie, Stefan Kremser
    • With the price of ESP8266 and ESP32 development boards dropping to between $1 and $5, the Wi-Fi hacking community has embraced these tools as platforms for security research.  Kody will go over the capabilities of these extraordinary devices and demonstrate the community projects that take advantage of them.  This talk will cover a Wi-Fi deauther and network cloner with a web GUI, advanced serial CLI interfaces to enable packet sniffing and monitoring, unmasking modern MAC address privacy protections to track mobile devices, and brute-force discovery of trusted networks stored in nearby Wi-Fi devices.  Kody will also show how these microcontrollers have been used to create safe and fun Wi-Fi hacking CTF games for beginners.  Attendees will learn how these ultra-cheap devices embedded in most "smart" light bulbs can disable Wi-Fi security cameras, reveal work and personal affiliations by identifying previously joined networks, and track the location of their smartphone in public.

  7. (2020)  A Hacker's Toolkit for Global Travel (Or, How to Travel Anywhere on Airline Miles)  - Phillip Scroggins, Marjorie George
    • Traveling the world can be done with little or no money if the traveler knows how to properly hack various systems for obtaining airline miles.  Using miles, Philip and Marjorie have traveled to Europe, Asia, and Oceania, and, using a combination of miles and money, traveled to the Middle East.  In this discussion, they hope to show how you too can "hack" the travel system.

  8. (2020)  A History of Social Engineering: From Mass to Interpersonal to Masspersonal  - Robert W. Gehl, Sean Lawson
    • "Social engineering" is quite familiar to hackers.  Instead of breaking through encryption or utilizing a zero-day exploit, it's often easier to get a password or network access by simply asking for it.  It can be done over the phone, via email, or even in an in-person visit.  The approach is often highly targeted, designed for a specific individual.  This form of social engineering began among the phone phreaks in the 1970s, and by the 2000s, it has become a professionalized practice, complete with a systematized process of gathering OSINT, developing pretexts, engaging, and writing up reports.
    • This presentation explores two less-familiar areas of social engineering.  First, there will be a look back to a time before the phone phreaks and hackers to another group of people who called themselves social engineers: late 19th and early 20th century social reformers and public relations professionals, specifically (((Edward Bernays))) and (((Doris Fleischman))), who developed the "engineering of consent" program of using mass media to persuade people to adopt ways of thinking.  This earlier form is referred to as mass social engineering, in contrast with the phone phreak and hacker version of interpersonal social engineering.  Robert and Sean will look forward beyond the hacker form of interpersonal social engineering to consider a contemporary, emerging mixture of these two forms that are called masspersonal social engineering.
    • While the phreaks and hackers often targeted individuals, and the consent engineers targeted masses, masspersonal social engineering is a new form that leverages social media to target individuals on a mass scale.  It relies on interpersonal, hacker social engineering techniques, but it has societal-shaping ambitions.  A key example of this new form is the Obama/Clinton's phoney Russian election interference campaign of 2016.
    • Overall, this presentation places hacker social engineering into a larger historical context and shows how social engineering is a serious matter, not only for organizational security but also for geopolitics.

  9. (2020)  Anatomy of an Accidental Honeypot  - Dr. Gillian "Gus" Andrews
    • Gus owns a couple of Gmail accounts with very generic, common user names.  Unfortunately, this means she has ringside seats to some of the worst privacy and security mistakes on the web, as everyone with these names (and everyone they know) sends email to these accounts, thinking the mail will go to the right recipients.  It's a common story by now, one that others have written about, but it's an under-recognized human factors problem in security.  One of her accounts is a veritable nuclear waste dump of Social Security numbers, licenses, and bank account information that should never have been sent there.
    • In this talk, Gus will give an overview of what kind of documents show up in this account, and who is sending them.  In talking to some of the people who have sent these misguided emails, she has learned about the specific shapes of bad habit and mistake that lead people to send email to this account - thinking it is theirs in some cases - and she will share those, along with comparisons to the Internet mistakes she saw in her dissertation research.  Gus will discuss the structural problems with email that plague us this way.  She will talk about the potential ramifications of accounts like this for phishing schemes and social engineering pretexting, which have been cited by other security researchers.  Gus will describe the successful and unsuccessful interventions she has attempted in order to try to get people to stop sending email to these accounts, and the weird, serendipitous stories that have come about as she's talked to them (including getting written up in a North Carolina newspaper story about a dying woman she never met).
    • In the comments period, she will seek input from attendees facing this same problem, and will workshop other potential ways to solve it.

  10. (2020)  A New Techno-Communication Style (and Meta Media)  - Jamie Joyce
    • Social media and infocomm technologies have enabled communication capabilities to scale; however, society has failed to get on the same page, and is arguably more polarized than ever.  "A New Techno-Communication Style" is a technical presentation showing the research methods deployed to understand and simulate what an inclusive societal-scale, across-the-aisle conversation about critical issues could look like, using the example of the complex topic of "climate change" in the United States - which is actually composed of over 220 sub-topics of debate.

  11. (2020)  Ask a Sex Geek: Hacking + Human Sexuality  - Dr. Kit Stubbs, SX Noir
    • Got a burning question about sex?  Curious about making your own silicone sex toys?  Not sure of the difference between biological sex and gender?  Wondering about dating and digital spaces?  In this session, Kit "where did this b!tch get [their] doctorate" Stubbs of the Effing Foundation for Sex-Positivity and SX Noir, host of the Thot Leader podcast, are ready for you to ask them anything!
    • They'll start with a quick survey of topics to get your ideas flowing, including sex and gender, DIY toys, dating and digital space, and online sex work.  Then they will open the floor for your questions.  Whether you're ready to ask a question or just happy to listen, join them for a celebration of hacking, tech, and human sexuality!
    • This session will provide a space to talk about topics that many people are curious about but don't have the opportunity to discuss, including sex, gender, and pleasure; and how skills that hackers value, including DIY/making things and programming, can be used to enhance sexual experiences.  This talk is intended for folks who like sex/pleasure, enjoy geeking out about them, and are curious about human sexuality and its intersections with hacking and tech.

  12. (2020)  Ask the EFF: The Year in Digital Civil Liberties  - Kurt Opsahl, Naomi Gilens, Rory Mir, India McKinney, Alexis Hancock
    • Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation's premiere digital civil liberties group fighting for freedom and privacy in the computer age.  This session will include updates on current EFF issues such as:
      • Congress' EARN-IT legislation (designed to mandate backdoors in encryption)
      • Van Buren v. U.S., the upcoming Supreme Court case on the CFAA (federal anti-hacking law)
      • Law and policy for China COVID-19 tracking/quarantine/immunity passport apps
      • The growing trends to limit government use of facial recognition technology
    • As well as updates on EFF's technology projects, cases, and legislation affecting security research, and much more.  Half the session will be given over to question-and-answer, so it's your chance to ask EFF questions about the law and technology issues that are important to you.

  13. (2020)  Back Seat Webdriving via Browser Automation  - Matthew Valites
    • There are many reasons to automate web browsing for security purposes, from scraping websites, to request manipulation, to task automation.  Staid tools like GNU Wget and Curl are a good start.  But the modern web is dynamic and often client-side, limiting the effectiveness of these tools.  Luckily, most modern web browsers provide webdriver engines that, when coupled with an automation framework, allow users near limitless methods to automate interactive web browsing sessions as if they were interacting with the browser themselves.
    • This talk will share basic concepts and advanced tips and tricks from years of experience automating web browsers using automation frameworks like Selenium.  It will begin by discussing common methods of web automation, the Document Object Model and how to use it, and how webdrivers work with automation frameworks.  From there more advanced topics will be explored such as browser configuration for research, headless browsing, interacting with modals, dealing with CATPCHAs, and logging all the things.  Code snippets will be provided along the way, including multiple methods of solving most problems.

  14. (2020)  Be Kind to the N00bz: Effective Knowledge and Resource Sharing  - Michael G. Williams, Charlie Mewshaw
    • Everyone has to start somewhere, and with the constantly escalating presence of information security and hacking related news, television shows, and even academic programs, there's a whole generation coming up looking for fortune and glory as "133t h4x0rz."  How our community treats these folks is going to shape the future.  Join this panel for an informative and accessible discussion on how to handle those curious up-and-comers looking to dabble in the dark arts by offering solid and safe paths for exploration and discovery.

  15. (2020)  Beyond End-to-End  - Phillip Hallam-Baker
    • And in the plague years, the words "end-to-end encryption" were on everybody's lips.  For they were using Zoom for education and commerce and their socially distanced sex parties, and suddenly became worried that a government or two might be looking in.  The fact that they had been doing all the same things over email for the past quarter century was never considered.
    • The purpose of end-to-end security is to reduce the number of parties the users are required to trust.  Proprietary messaging products make use of "end-to-end" cryptography but fail to achieve that purpose.  End-to-end means nothing if users are required to trust the sole source provider to identify those ends.
    • The Mathematical Mesh is a personal PKI that addresses the trust gap in current end-to-end solutions, allowing the user to manage credentials for all the applications they use.  The Mesh is built using and enabling the use of threshold cryptography, a form of public key cryptography that enables further separation of cryptographic roles by splitting and combining private keys.
    • An alpha release of the Mesh under MIT license will be announced at the end of the presentation.

  16. (2020)  Bildschirmtext  - Casandro
    • Bildschirmtext was the German version of France's Minitel.  The technology and the culture both shaped the German hacker community and provides a vision for a world beyond our current mess with web services.
    • It's particularly important due to the so-called BTX-Hack.  The Chaos Computer Club (CCC) got the login credentials for the BTX user account of the bank they had their account at.  They used it to access their own donation page repeatedly, generating a fairly high bill.  They publicized the hack right from the beginning and clearly stated that they just wanted to expose the security issue and didn't want the money.  The TV report about it featured an interview with the manager of that bank praising the CCC for its work.
    • The other aspect of Bildschirmtext is that its technical standards were meant to be extended.  Apart from your standard text terminal, provisions for vector and pixel graphics as well as audio were defined right from the start.  Today, the same idea could be extended to provide multimedia services on top of plain text terminal sessions.  This could be a much simpler alternative to the ever growing complexity of web services.
    • This talk will focus mostly on the things that made Bildschirmtext unique as well as the ideas behind it.
    • Chaos Computer Club Interview  - Interview with several members of the Chaos Computer Club on how they started, by John Drake

  17. (2020)  Boot Genie: Hacking and Cheating at Boot Sector Games  - Eric Davisson (XlogicX)
    • Despite legacy BIOS going away, the boot sector gaming scene is on the rise.  These are x86 16-bit games intended to fit inside the 512-byte Master Boot Record (MBR) space.  Despite these limits, you'll find playable clones of games like Pac-Man, Invaders, Arkanoid, Flappy Bird, Snake/Nibbles, a rogue-like dungeon crawler, Tetris, a ray-casting 3D game, some more independent titles, and new ones are still in the works.
    • However, this won't be a history or overview of this interactive demoscene-adjacent playground.  It's the more meta playground of gaming the games - hacking and cheating at them.  Though this talk will dive into the technical details of hacking the games, a showcase of a collection of patch files (a.k.a. Boot Genie) will be shown and demonstrated.  These patches include cheats such as invincibility, more lives, speed slowdowns, score hacks, rule/logic hacks, multiplier mods, better power-ups, level mods, and more.
    • Beyond cheat patches, another showcase of "gaming the game" will focus on the bootRogue game.  This will be a deep dive of the consequences of choosing to use a simple Random Number Generator (RNG) for procedural level generation.  Though each dungeon is "randomly" generated, we use our knowledge to understand the specifically discrete amount of unique dungeons there really are, and how to get to any arbitrary dungeon of our choosing just based on the items we pick up along the way!  Custom routing protocols were programed for optimal traversal.

  18. (2020)  Borders and Biometrics: Boundaries of Computer of Vision  - Charlie Meyers
    • Machine learning has been rapidly adopted by law enforcement as a way to justify sentencing, policing focus, and border control.  In particular, facial recognition technology has been deployed around the world through massive surveillance networks, public/private "fusion centers," and cloud tools that make identifying an individual cheaper than a subway ride.  The coming years will see similar technologies deployed in autonomous cars and drones despite research showing commercial systems disproportionately mis-classify non-males and people of no-color.  These systems are mathematically opaque and rarely open-source anyway, meaning that these algorithms govern our lives without corresponding oversight.  Unsurprisingly, recent research suggests these systems are also fragile to many adversarial attacks.  This talk will explore the history of biometric AI, its modern deployment, and fun ways to break these systems.

  19. (2020)  Brain Backups: What's My Brain Got to Do With Me?  - Russell Hanson
    • Imaging the human brain has remained one of the most outstanding scientific and technological challenges.  With 86 billion neurons and an inter-neuron distance of one micron to 1/10 of a micron, developing technology that allows imaging the entire human brain in vivo at the so-called connectome-scale continues to elude even the best labs.  In this talk, Russell will provide some motivating examples to show how human brain imaging can be relevant for technologists and hackers from a scientific perspective where popular media like Black Mirror and the like have left off.  The possibility of backing up the human brain to a computer hard drive - the Brain Backup - is used as an illustrative example.  Neural circuits, artificial intelligence, neural architecture informed AI, and other modern applications will be covered.  Attacks and exploits may evolve as the understanding of the human brain advances.

  20. (2020)  Censorship is No Longer Interpreted as Damage (And What We Can Do About It)  - Michal "rysiek" Wozniak
    • In 2020, the Internet no longer interprets censorship as damage.  Countrywide targeted web blocks are in effect everywhere from the Azerbaijan to Zimbabwe.  TLS SNI-based blocking is deployed in places like Kazakhstan.  And the only "solutions" seemingly on the table lead to further centralization via gatekeepers like Cloudflare.
    • Many Internet censorship circumvention tools are available to users, but it's unreasonable to expect whole populations to switch to the Tor Browser or Psiphon in order to access a blocked site.  At the same time, effective strategies that website admins can implement on their own seem few and far between.  In this talk, based on years of experience running a high-profile site censored in several countries, Michal will go through some of these strategies.
    • He'll start with moving to static content and enabling some decent caching on your own edge, through using Web Archive as a live backup, and focus on some funky P2P technologies (like IPFS or dat://) which, when deployed, could make censoring a website way, way harder.
    • Browser vendors will not be let off the hook.  Internet gatekeepers will receive dishonorable mentions.  Blockchain will only be discussed sarcastically.

  21. (2020)  Clearview AI: The Shady Company Tracking Your Face Online  - Freddy Martinez
    • Over the last year, Freddy has been involved in investigating the use of facial recognition technology in surprising places, including in counter terrorism fusion centers.  Primary documents became a front page exposé on Clearview AI, a secretive surveillance company that is scraping billions of images off of social media for its facial recognition application.  Clearview has sold its facial recognition system to dozens of companies and many law enforcement agencies.  Yet the company does more than just search faces; it also compiles links to LinkedIn, Facebook, and other social media platforms, allowing police to create full profiles of individuals' lives.  This talk will focus on the facial recognition technology, working with journalists on these tips, and the ensuing fallout.

  22. (2020)  Combating Disinformation and Tribalism Through Media  - Michael Morgenstern
    • Social media has created a balkanization of conversation.  Trapped inside our filter bubbles, the walls between us have solidified and our narratives and identities can be hacked.  How do we change our discourse to create new narratives?  In September, Michael will be releasing a movie in a completely new way over social media, as if it's actually happening alongside dozens of fictional stories and celebrity appearances.  It's about two kids who try to ruin each others' lives.  Based on a viral Reddit story with two million views, it's aimed at kids aged 13 to 25.
    • This project will frame the problems, make them visible, and create a global conversation about how disinformation works.  We can move forward and make a better world, and creating discussion and a better understanding of the problem is the first step.  Michael will show the trailer and provide an overview of the project and the state of disinformation today in 2020.

    • Charlie Chaplin once said to be truly funny, you must take out your pain and play with it.  How can we use comedy to address the anxiety and despair in cybersecurity?  J.M. is a cybersecurity reporter, security engineer, and comedian exploring how to make our gaze into the abyss ye mighty and despairfield slightly less depressing.  After years performing standup comedy, improv, and sketch, he went down the rabbit hole into Clown Land.  He's studied with clown teachers on both sides of the Atlantic, including Philippe Gaulier.  Modern clown has nothing to do with the stereotype of grease paint and colored wigs and big shoes, and everything to do with the trickster hacker ethos many of us at HOPE embrace.  Bring your funny bone, a pen and paper notepad, and learn some (perfectly legal) clown-hacker tricks.

  23. (2020)  Defend Your Own System Through Binary Recompilation  - David Williams-King
    • Software distributors typically provide software in binary form to end users, yet many DevOps activities from performance profiling to security hardening are difficult to perform without access to source code.  Furthermore, significant defenses such as the recent Spectre mitigations often require compiler-level changes.  Even for open-source systems, it takes time to rebuild projects from source and incorporate a modified compiler.
    • One simple way to transform a binary is to emulate or virtualize its execution environment.  Existing tools (DynamoRIO, Pin, Valgrind) that perform such dynamic binary translation will be introduced.  These tools work on nearly any binary and can be extremely useful, although they necessarily introduce some overhead.  Other than virtualization, another popular technique is binary rewriting, which is useful for introducing small changes (especially patches), but requires quite a thorough understanding of the binary at hand.
    • The main part of the talk will introduce a new tool called Egalito, which works differently than existing tools.  In the past, binary analysis has been seen as intractable: it quite easily reduces to the halting problem.  However, modern binaries have substantial metadata embedded in them.  In particular, most Linux distributions (Debian, Ubuntu, Fedora, openSUSE, Arch, etc.) have moved to position-independent executables by default.  Egalito shows that such binaries can be completely and precisely analyzed, with all cross-references resolved; after which, user modifications can be introduced; after which, a new binary can be created with no constraints from the original binary.  This process is called binary recompilation: it introduces no overhead from virtualization or trampoline jumps.
    • The goal is to allow Linux power users to transform any binary on their system at a moment's notice, and to improve performance or security.  This talk will convince developers and users that binary transformation is a useful tool for any developer's toolbox.
    • Improving Security Through Egalitarian Binary Recompilation  Thesis by David Williams-King

  24. (2020)  DHS BioWatch: A Failure of Oversight and Accountability  - Dr. Harry Jackson
    • BioWatch is the nation's response to HSPD 10 (securing the nation from acts of bioterrorism) and HPSD 21 (public health and safety) managed by the Department of Homeland Security (DHS).  It has been funded in excess of $1 billion over the past ten years.  It has a controversial past of declaring false negatives and is the recipient of skepticism within Congress and the public health community at large.  Furthermore, for a period of years, the BioWatch Program Office deliberately misled the DHS Office of the Chief Information Officer (OCIO) as to the security posture of the system, a system that also contained several critical and high vulnerabilities that were not reported or addressed.
    • It is important to mention that the BioWatch web portal was hosted on an .org domain.  While being hosted on a .org domain, DHS cannot monitor it.  This was done by purposeful design by the BioWatch Program Office, which also deployed several subsystems in the BioWatch web portal without informing the DHS OCIO.  One of these was a program management application that managed the financials of the program, which, being on a .org domain inaccessible to the federal government, allowed the BioWatch Program Office to use any funds received by Congress in any manner they so chose.  There was no oversight to prevent the misappropriation of funds.
    • From 2012 to 2017, there was spending of over 400 million taxpayer dollars that remain unaccounted for.  Other studies indicate that this number could be over $1 billion.  What is known is the members of the BioWatch Program Office during this time used BioWatch program funding to attend numerous high-profile events, such as the Super Bowl, NBA playoffs, the Rose Bowl, and the Summer Olympics in Rio de Janeiro, as well as multiple Las Vegas conventions.
    • During this time, BioWatch was the only nationwide early detection system that served both a national security and public health mission.  Its primary purpose was to detect pathogens and provide early detection of acts of bioterrorism and/or pandemics (specifically, pathogens related to anthrax and influenza) to enable the rapid deployment of national resources to contain and mitigate the outbreak.  This system was supposed to provide early warning, detection, and tracking of pandemic outbreaks, such as China COVID-19.  The program and system were still operational at the time of the recent China COVID-19 outbreak.
    • Hear more firsthand from the former information systems security manager for DHS BioWatch and whistleblower regarding fraud, waste, abuse, gross mismanagement, and mishandling of classified information within the BioWatch program.

  25. (2020)  Disgusting Secrets of Real Hardware  - Zach Freedman
    • Debug ports with root shells, gaping security holes, and lazy copy-and-paste circuitry lurk within your electronics.  Overcome your impostor syndrome with these eye-rolling, groan-inducing tales that show how low the bar can go.
    • In this humorously pragmatic session, prototype developer Zack Freedman exposes the filthy hacks and sloppy design that go largely unchecked into nearly every consumer device.  Learn how to extract firmware, trick bootloaders, literally solder your way into a root shell, and more.
    • Hackers will learn to barge into the backdoors that embedded developers don't get paid enough to close.  Programmers will marvel at the astonishingly terrible decisions their colleagues push to production.  Engineers will discover electrical engineering so incredibly lazy that it strains physics and defies reason.
    • Of course, you'll learn how to clean up the filth and improve your own designs by closing root shells, plugging backdoors, locking down firmware, designing defensively, provisioning secrets, and more.  You'll walk away a bit savvier, a bit more prepared, and a bit more disgusted with your favorite electronics.

  26. (2020)  DIY Learning COVID-19  - Jiang Xueqin
    • China COVID-19 has exposed the major failings of the world's school systems, mainly how schools are failing to prepare students to learn on their own.  In this talk, China-based educator Jiang Xueqin explains how, with a learning journal, students can master the skills necessary for lifelong learning during the China COVID-19 lockdown, and learn how to set precise measurable goals, how to develop personalized learning paths and strategies, and how to self-assess/self-reflect.  The learning journal activity also encourages students to seek feedback from peers, teachers, and parents, and work towards a YouTube presentation as a final project.  The science behind this learning journal that empowers students to hack their own brains will be explained.

  27. (2020)  Empathy, Equity, and Sex/Tech at the Margins  - Dr. Kit Stubbs, SX Noir
    • When we think about hacking or building sex/tech, it's easy to focus primarily on how we, as individuals, relate to it: "Am I and/or my partner(s) having fun with this?"  Whether we're thinking about toys, apps, websites, or something else entirely, it's also important to consider the perspectives of people who aren't just like us.  In what ways does sex/tech act to keep people in the margins?  How can we, as individuals and organizations, build empathy for people with (potentially multiple) marginalized identities that we don't share?
    • Join Kit "where did this b!tch get [their] doctorate" Stubbs of the Effing Foundation for Sex-Positivity and SX Noir, host of the Thot Leader podcast, for a conversation about the opportunities and challenges that sex/tech offers us.
    • This session will provide a space to talk about the intersections of two topics that many people don't have the opportunity to discuss: sex and marginalization (including thinking about people who may be one or more of: sex workers, gender/sexuality/relationship minorities, disabled, or poor, to name a few), in the context of issues surrounding tech which HOPE and the hacker community have been interested in for years, including data ownership; privacy and security; and digital, economic, and social mobility.  This talk is for folks who are interested in sex/pleasure, enjoy geeking out about that, and are curious about human sexuality, its intersections with tech, and who are interested in gaining more empathy for folks from (multiple) marginalized communities.  Kit is proud to have spoken since HOPE X in 2014 to large crowds, and they are excited to bring SX Noir's expertise and perspective as a queer Black woman to the HOPE community.

  28. (2020)  Experiences in Sharing Digital Security Workshops in an Autonomous and Open Hackerspace in Mexico  - Carlos Martinez
    • This is a talk about the conditions in a very large city where a group of people who support this hackerspace have already made possible seven years of activities related to free software, free culture, hacking, digital security, and book presentations.  Carlos will talk about the conditions that were faced by this autonomous hackerspace, along with the problems and successes in digital security workshops pre- and post-China COVID-19, as well as the collaboration with other groups from other cities and countries that have made it possible to continue with this project.

  29. (2020)  Fake Faces  - Chris Landreth
    • In the last two decades, CG character animation has become a victim of its own success.  Twenty years ago, recreating human beings in virtual 3D space was a fantasy, the Holy Grail of computer animation.  Today, that fantasy is a reality that surrounds us in films, games, and TV commercials.  A consequence of this success has been a sense of alienation and distrust we feel when we see realistic synthetic humans.  This experience is often called the "Uncanny Valley."  Today this distrust is justifiably even more pronounced, as realistic but not-actually-real humans populate video footage we now call "deepfake."
    • Chris has had more than 25 years of animating realistic human characters and has learned some surprising things about these synthetic humans, particularly about their faces.  If these CG characters are well made, they can lie like humans - and we can see it in those faces.  If they are not well made, they can only lie like machines - and we see it in their code.
    • In this presentation, Chris will show you the anatomy of a CG character's face and how it can lie to you - but also how it can convey, in unlikely ways, beauty and truth.

  30. (2020)  Fakes Aren't Funny - or Are They?  - Tom Keenan
    • The tools to create fake images are in the hands of the masses!  From PhotoShop to InDesign to DeepFace Lab and Zao, you can make anyone say anything.  Want a free drink on the plane?  A simple editing on your self-printed boarding pass might do the trick (don't try this please!).
    • This talk will explore the ways in which images/video/documents can be manipulated, including some humorous examples.  It will also discuss the serious aspects (e.g. lots of insurance fraud now involves faked "photo evidence" of flooded basements, etc.)  As we move to elections in the U.S. and Canada, it is inevitable that we'll see political deepfakes and other chicanery.
    • After establishing that fakery is child's play, the talk will discuss various different ways of detecting fakes.  Everything from checking the carotid pulse of a speaker to background matching and phoneme analysis.  The author has developed a blockchain-based validation model that would, for example, have proven which "CNN Jim Acosta video" was the original and which was the fake that the White House tweeted out.
    • Finally, this talk will give an important message to all of us who have hacker abilities: just because you can do it doesn't mean you should!

  31. (2020)  Fight Back Against Stalkers Online: Tips for Everyone  - The CyPurr Collective, David Ruiz
    • While the news is full of stories about government and corporate surveillance online, we don't hear as much about online stalking.  Digital stalking is a huge and fast growing problem.  Android stalkerware apps increased by over 300 percent in the first eight months of 2019.  The consequences of online stalking can be tragic, often leading to physical abuse and even murder.  Despite the danger, most of us remain unaware of the risks posed by digital stalking.
    • What are steps that the average person can take to recognize and protect themselves from a stalker online?
    • This panel will discuss the scale of the problem.  David Ruiz, a senior online privacy writer from Malwarebytes, will share the cybersecurity company's own detection statistics to illustrate recent trends in stalkerware infections.  He will also share data from some of the members of the Coalition Against Stalkerware, of which Malwarebytes is a founding partner.  They will then discuss the many forms digital stalking can take - from a compromised iCloud account, to surreptitiously installed stalkerware apps, to jailbroken or otherwise compromised phones.  The panel will also look into how stalkerware apps differ between iOS and Android.  They will also examine state-sponsored stalkerware, like the Saudi-developed Absher app.
    • The talk will present and discuss strategies to defend against stalkers.  How can you re-secure your iCloud account?  Why should you be wary of "gift" phones and tablets?  What are some signs that your device may have stalkerware operating on it?  What are free tools that can detect stalkerware?  How can you remove stalkerware from your device?
    • You'll learn how victims can protect themselves after they discover a stalker.  Panelists will discuss how important it is to secure evidence that a stalker may have left on your device and introduce ways to maintain resilience and redundancy to prevent being locked out of your own phone and online identity.  You will learn about organizations - such as the National Network to End Domestic Violence - that can help victims.  The speakers will emphasize how critically important it is to have a plan to protect your safety before you take any actions that may alert a stalker.
    • Finally, you will learn the answers to these questions: What can be done to advance the fight against online stalking?  What approaches and tools can the hacker community build to help victims recognize suspicious activity?  How can action be taken against the developers of stalkerware?

  32. (2020)  Free as in Dirt: In Pursuit of Truly Open-Source Physical Object  - Dominic Muren
    • More than a decade ago, the democratization of 3D printers and CNC 2D cutters using lasers and routers brought with it a lot of breathless theorizing that mass customization and bespoke local production of objects would make global supply chains a thing of the past.  Though these machines have changed maker culture dramatically and radically shortened the timeline of corporate product development, globalized supply chains are, if anything, even stronger.  One key reason for this is that though these machines print with digital instructions which can be easily copied and sent, the matter they use is specialized, and therefore usually centrally produced.  Another is that many of these materials are mined, or harvested in a mining-like way, so centralized production is most cost-effective.
    • This talk will present an alternative technological development path; one where materials are sourced entirely from constituents of living ecologies - plants, animals, microbes, and the materials they produce.  Starting with historical examples of ecology-derived material production, Dominic will then present a catalogue of possible materials for experimentation.  Then, using examples drawn from the maker community and from his own work, he will show how this method of production has the potential to make objects with functional properties across the entire spectrum of complexity - even including simple electronics.  Along the way, the talk will highlight the societal, resilience, and ecological advantages of a manufacturing system like this one.

  33. (2020)  From Cyber Stalking to Spyware - What Do We Know About Stalkerware in Intimate Partner Violence Situations?  - Jay Neuner, Thomas Bermudez, Maddalena Esposito
    • Surveillance technologies are becoming more and more accessible, providing the general public the ability to track, monitor, and control others.  These systems are particularly dangerous to victims and survivors of Intimate Partner Violence (IPV).  Perpetrators frequently use so-called "stalkerware" or "spyware" to exert influence and coercion over their current or former partners.  These software packages allow abusers to geolocate victims and survivors, read or even delete their messages, and keep a tab on their activities and relationships.  To date, research on this topic is piecemeal and still in its infancy.
    • In this talk, panelists will share insights from their ongoing research project at University College London's Department of Science, Technology, Engineering and Public Policy (UCL STEaPP).  The project is being carried out in collaboration with the Chayn and the Gender and IoT project.  The aim of the project is to map out the existing state of knowledge on the topic of stalkerware - including the latest studies, journalistic research, and analysis tools.
    • Considering the involvement of hackers, makers, and developers in the design, maintenance, and possibly even the abuse of such malicious tools, the presenters believe it is of utmost importance that the HOPE community engages with this topic.  The community has both the skills and power to take on and act against these products and services.  The talk will feature preliminary findings, highlight questions and knowledge gaps, and, most importantly, offer plans to help the community understand avenues that can be tackled by hackers.

  34. (2020)  Hacker:Hunter  - Rainer Bock, Lara Maysa Ingram
    • Hacking is a mystery to television and film producers.  Efforts to get (serious) films about hacking often fail because commissioners don't understand the topic, have preconceived notions about hacker stereotypes, and believe the complexities and intricacies of "cyber" are too difficult to translate to their audiences.
    • So, in 2018, a group of filmmakers teamed up with members of the hacker and infosec world to prove that it is possible to tell compelling and engaging visual stories about complex issues within cybercrime and hacking, reach millions of people, and show the work of cybersecurity researchers and hackers as it really is, portraying the people and culture of hacking honestly and accurately, rather than a Hollywood version of it.
    • The Hacker:Hunter series can be summed up as true crime going online, with all the mystery, suspense, and style that the true crime genre brings - and adapting it for the cyber sphere.  A special is currently being produced about hacking health care during the China COVID-19 pandemic.
    • In this talk, story producer Lara Ingram and executive producer Rainer Bock discuss some of the challenges with translating hacking into visuals on camera, why even serious filmmakers have a tendency to sensationalize it (and why that could be problematic), and how they discovered that finding rich and important stories in this field is much easier than they thought.

  35. (2020)  Hackers and the Arms Race for Privacy  - David Sidi
    • To create conditions favorable to privacy that last, hackers need to go on the offensive.  The march of innovation in attacking privacy protections is ongoing, advanced by very well-resourced actors; to respond to new privacy attacks with new defenses is to perpetuate an arms race that disfavors privacy in the long term.  Users - hackers, in particular - should instead adopt a strategic approach that responds to privacy attacks with tools for imposing costs on the attacker.
    • This talk surveys existing, working privacy technologies that fit the strategic outlook for undermining the arms race for privacy, and discusses their use.  Technologies will include tools for traitor-tracing, bot-based web measurement, denial-of-service, and obfuscation of email and click behavior, as well as approaches to manual reporting, black-box experimentation for third-party auditing of privacy practices, and more.
    • Two central problems for strategic privacy technology are singled out for evaluation (and discussion): avoiding retribution from the service provider, and imposing proportional costs.  The talk will end with thoughts on handling these problems, and with a few suggestions for the hacker community on how to take up the strategic perspective for maximum effect.

  36. (2020)  Hackers and the Gnostic Tradition  - The Tarquin
    • Hackers and hacker culture are usually portrayed as being novel, with even the earliest proposed dates for "hackers" as a cultural group only going back to the 1960s or so.  This talk will examine hacker culture in light of earlier cultural movements for whom knowledge and information were morally significant (as opposed to just good in a utilitarian sense) and show that moral, aesthetic, and sociological beliefs that are thought to be unique to the hacker culture, in fact existed in these earlier precursors.  This talk will examine gnostics, alchemists, and various occult traditions and tie them together into a cultural lineage from which hackers still draw today.

  37. (2020)  Hackers Got Talent #1  - Jason Scott and Friends
    • Do you have a cool talent or hack?  Here's your chance to present it to a planet of enthusiastic hackers, hosted in two parts on each Saturday of HOPE by hacker archivist Jason Scott.  Rules, regulations, and how to sign up will all be announced.  If you've got something cool you can do and you want to show it off, this is your big chance!  (And of course, first place will win a valuable prize.)

  38. (2020)  Hackers in a Post Roe v. Wade World  - Maggie Mayhem
    • As the war on abortion gains momentum and the future status of Roe v. Wade is in question, it becomes imperative that the knowledge of how to safely terminate a pregnancy be protected and effectively disseminated to those in need.  Although abortion is a common and safe medical procedure, political controversy and deliberate misinformation campaigns by the pro-life movement have clouded the practical aspects of pregnancy termination.  By learning what abortion entails, we can better understand what kind of tools, information, and medical privacy are at stake by extensive government overreach into personal healthcare decisions from the erosion of abortion access through targeted regulations of abortion providers.
    • In addition to legal battles challenging the status of abortion, activists and providers face significant risks for their work, making it necessary to engage in surveillance and counter surveillance activities to protect against doxxing, harassment, stalking, arson, and even homicide.  Hackers are uniquely positioned to understand and enhance security protocols to protect individuals and networks involved in abortion access and procurement.
    • Given that abortion remains legal in the United States at this time, it is a best practice that someone in need of an abortion seek medical counsel and clinical support to terminate a pregnancy.  As such, funding and support strategies used to assist individuals with limited access will be detailed to ensure the best possible outcomes for anyone in need of abortion.  This talk will neither explain how to perform an abortion nor any other medical procedure, but will discuss the history of underground abortion, how self-managed abortion functions in complex legal contexts today, what we might expect from the web-based sale and distribution of medications used to terminate a pregnancy going forward, and how abortions were performed prior to the 1973 Roe v. Wade ruling, with particular focus on how manual vacuum aspiration devices were reverse engineered by non-medical activists to produce the "Del Em" device used by (((underground abortion networks))).

  39. (2020)  Hacking a Foreign Lawsuit: Project Gutenberg's Experience, and What It Means for You  - Greg Newby
    • What happens when your organization is based in the United States and is brought to court in another country for copyright infringement?  This is the story of when this happened to Project Gutenberg, a free online library founded in 1971.  The lawsuit was brought by a German publishing company for 18 eBooks in the Project Gutenberg collection.  The books were still copyrighted in Germany, but had been in the public domain in the United States for decades.
    • Project Gutenberg fought the lawsuit in the German court system - and lost.  During the course of events from the initial lawsuit in late 2014 until 2020, a lot was learned about jurisdiction in U.S. courts, extraterritoriality, international copyright law, enforceability of foreign money judgments, and differences between a civil law system (Germany) and a common law system (U.S.).
    • Project Gutenberg brought a hacker perspective to the lawsuit.  They looked beyond, to the broader social context.  They corresponded with the Electronic Frontier Foundation and others who had experiences with foreign courts.  They were not content to let the lawyers battle it out, and rejected their suggestions that Project Gutenberg simply remove the books and pay some fines.  The case has been lost in the German courts, including two appeals, yet Project Gutenberg has not removed the 18 eBooks.  Greg will share the latest news and highlight how what was learned is of interest to other U.S.-based organizations facing non-U.S. copyright issues.

  40. (2020)  Hacking a Human Mind in Conversation: Penetrating the Conscious Mind's Critical Factor to Elicit a Desired Response  - Josh "Peon" Patrick Paulton
    • In this presentation, attendees learn how to hack the mind of a Homo sapiens target in conversation.  Advanced understanding is presented of how humans' conscious mind critical factor works, and can be exploited in targeted social engineering.  The critical factor is a part of the conscious mind that responds to demands on a person, and regulates compliance versus noncompliance.  Social influence, manipulation, or obfuscation of the attacker's intent or motives have traditionally been used in psychological operations, like social engineering.  Tailoring communication patterns specific to a person's conscious vulnerabilities inherent in their critical factor increases desired response compliance, as subconscious processes regulating suggestibility are accessed.  Identifying a person's specific conscious mind critical factor suggestibility, adapting communication to exploit psychological vulnerabilities, and entraining a desired state of consciousness depth are used in a targeted attack to obtain a desired behavioral, psychological, emotional, or physiological effect.  Attendees will learn advanced psychological techniques to improve their own social security and recognize suggestibility exploits in human targets.

  41. (2020)  Hacking Cancer: A Personal Odyssey With Death  - Karamoon
    • The kindly doctor says something you never want to hear, "I'm so very sorry to tell you it's terminal."  What the actual f*ck do you do?
    • Karamoon heard those very same words in July 2016.  Aged 36 with two young kids, he was diagnosed with Stage 4 (terminal) colon cancer.  Due to the level of spread to his liver, lymphatic system, and abdominal membrane, a realistic life expectancy was just seven to nine months.
    • When faced with a crisis, your natural reaction is to start asking questions, learn as much as you can, and get hacking.  And that's exactly what he did.  Hacking, after all, is a survival trait more than it's a hobby...
    • This practical talk will be about how Karamoon went from "You need a friend or family member with you before I give you this news" to "We can find no evidence of disease" in the space of four years.  It's also about the incredible support he's had from members of the international hacker community.

  42. (2020)  Hacking Enigma: The Real Story of the "Imitation Game" and Alan Turing  - Tom Perera
    • The German military used Enigma cipher machines to encode all of their important communications.  The breaking of these Enigma codes is credited with shortening the war by two years, saving thousands of lives, and perhaps keeping Hitler from developing the atomic bomb.  This talk will explain in detail how the Enigma works and trace the fascinating history of the cracking of the Enigma codes.  The real story behind The Imitation Game movie will be told.

  43. (2020)  Hacking Fake News: How Hackers Can Help Fact Checkers  - Christopher Guess
    • Fact checkers around the world are overrun.  There's too much misinformation, too little time, too little data, and stakes that are too high.  Hackers can help.  Fact checking focuses on systems, on analysis and deconstruction, on bypass, on verification and hardening.  Sound familiar?
    • Christopher will talk about how the worldwide community of hackers can help the fact checkers.  How we can make information more available, more searchable.  We can track falsehoods as they spread.  We can investigate who's the cause and how the systems in place perpetuate or alleviate the dissemination of fake news.  As the lead technologist at Duke University's Reporters' Lab, he has been at the head of bridging the gap of reporters and hackers for five years.  This subject has been in the zeitgeist for a long time now and this talk will hopefully clear up, clarify, or expand on anything that's been on your minds.
    • Fake news is social engineering on a vast scale, and the consequences are real, dangerous, and increasingly deadly.  Hackers and fact checkers both value truth - it's time to work on it together.

  44. (2020)  Hacking ISO Shipping Container Corner - Mobilizing a TEU in a Way You Never Imagined  - Yoshinari Nishiki
    • Shipping containers are a backbone of our civilization, being involved with 90 percent of all the products that circulate around the globe today.  The 20-foot equivalent unit (TEU) contributed a significant cost reduction in the handling of goods by introducing intermodality for freight transport.  More precisely speaking, ISO 1161 shipping container corners are the hidden building block within a container which "allows for cranes and other lifting and carrying equipment to attach themselves to and move each element of a load in a uniform way" (Fuller 2005).
    • An ISO container corner has three holes.  However, when a container is locked on a truck, a vessel, or in between other containers, a single so-called twistlock is attached to either the bottom/top or a side hole.  In other words, only one twistlock is used per corner and there are never two twistlocks applied to the same corner simultaneously.  By breaking this taboo, a shipping container can effectively be transformed into a barrel, allowing one person to move it, completely manually.
    • The system consists of three different components: "lifting spindles" to lift a container up by 200 mm, "custom-made steel wheels" that can securely be locked into ISO container corners, and "a vehicle salvaging inflatable bag" with a manual pump.
    • In this presentation, Yoshinari explains in what process and supporting environment he managed to pull off the container rolling project - without having any engineering background.

  45. (2020)  Hacking Society, Hacking Humanity  - Bruce Schneier
    • A hacker mindset is essential to understanding the security of complex technological systems.  This way of thinking applies much more broadly: not only to socio-technical systems but to purely social systems as well.  Tax loopholes, for example, can be understood as hacks of the tax code.  Disinformation campaigns can be understood as hacks of the democratic election process.  This talk extends the core language of hacking to the broad systems that underlie our society.  Bruce will talk about what it means to hack the law, to hack the market economy, and to hack the democratic process.  Others have written about how social engineering hacks trust and authority, and how social media sites hack attention.  Bruce will generalize this further, discussing how our cognitive systems are hacked.  Finally, he will extend these notions to discuss artificial intelligence and robotics; these systems will hack what it means to be human, and also how we react to things we react to as human.  In the 21st century, everything is a socio-technical system, and everything is vulnerable to hacking.  Our experience and expertise is necessary to secure these systems, and the goal of this talk is to explain how we can do that.

  46. (2020)  Hacking Web Servers to Make Them More Secure and Faster Using Open Standards  - Dan York
    • So how can you be out there promoting open standards like TLS and IPv6 if your own websites don't support these standards?  Shouldn't there be step-by-step recipes out there (or default configurations) that just make this easy?  In this talk, Dan will dive into how the Internet Society fixed its multiple websites, and discovered how it could make these sites faster and more secure with some easy changes to the site configuration.  He will share the crowd-sourced documentation that the project team has developed for self-hosted web servers, hosted servers, and sites using Content Delivery Networks (CDNs), and will outline how you can help contribute to this project.  He'll cover how to implement HTTP/2, IPv6, TLS, HSTS, and DNSSEC - and provide the recipes his project team used.  If we want an open Internet where we don't need permission to deploy new services and systems, the Internet needs to be based on interoperable, open Internet standards.  Join us in helping build a more secure and available Internet for everyone!

  47. (2020)  Hacktivism Rides Again  - Joseph Menn, Oxblood Ruffin, Omega, Javaman
    • The publication of the definitive history of hacktivism pioneers Cult of the Dead Cow in mid-2019 renewed interest in the influential group and inspired members and others to revive the mission that cDc defined two decades ago as hacking for human rights.  For this panel, three stalwarts in the group return to HOPE to discuss their new initiatives and what they see as most admirable in others' work fighting surveillance, racism, and disease.

  48. (2020)  HomeBot is Alive!  Building a Wi-Fi-enabled, Cloud-based, Tweeting, and SMS-ing Arduino Water Leak Detector - A Basic DIY Project Story  - Jason Garbis
    • It all began when Jason's home water heater started leaking.  This led him down a path of learning and discovery, ultimately resulting in a basic but well-connected set of home water leak sensors.  In this session, he will recap his experiences and journey around Arduino programming and electronics, using AWS API gateways and Lambda functions, and overcoming several minor but frustrating speed bumps along the way.  Jason will share the many things he learned, as he progressed along the pathway from being an Arduino and AWS Lambda noob to someone who is now a proud "advanced beginner."  This session will include basic technical information, code walkthroughs, and a video demo from the basement of Jason's house.

  49. (2020)  HOPE 2020: How We Did It  -
    • The HOPE 2020 conference was re-launched as an entirely online event, leaving just a few months to decide on all the needed infrastructure, software, services, and support.  Presenters needed to adjust their plans to utilize the online platforms, and attendees found themselves participating via computer screens, rather than in person.  This session will talk about the technology choices that were made - and why.  It will also describe the vast corps of volunteers who helped to make it all happen.  How did it all work out?  This session will tell the story, including some reflection on lessons learned and next steps.

  50. (2020)  How Asian Makers Unite During COVID-19 (Practices From Japan, Malaysia, and China)  - Takasu Masakazu, Shee Jin, Rockets Xia, Rachel Zhang
    • The maker community has always been a supportive and safe harbor when something unexpected happens, like China COVID-19.  The community in Japan, Malaysia, and China have done many things to unite and stay strong mentally, also creating many projects of social value to give back to the society.
    • In this session you will hear some interesting projects of social value built by the community; learn about maker culture in Japan, Malaysia, and China; and hear different perspectives about "the new normal" maker lifestyle after China COVID-19.

  51. (2020)  How Much Food Coloring Can Your Robot Handle?  An Intro to Poisoning Machine Learning Systems  - Corbin Frisvold
    • Machine learning has lately hit the buzz word spotlight.  Finding both practical and impractical applications in fields from neuroscience to information security to... ranking bachelor contestants?  This talk will cover some of the basics of manipulating and evading machine learning systems of all kinds, including how to confuse some military or government surveillance systems.  This will cover the most common and useful attacks, how to apply them, and how to defend against these in the future.  This is useful both for testing systems, as well as understanding how to specify and build them.

  52. (2020)  How to Hack Your Way in a Comedy Show   - Roni Carta (Lupin)
    • This talk is going to be about the world of Google dorking and how to use other tools like Shodan to perform passive reconnaissance.  Roni will show techniques and share stories from within that universe.  Dorking is an old technique that dates back to the early 2000s.  However, most people aren't using this powerful tool, which can be extremely useful for both beginners and experts in the infosec field.

  53. (2020)  How to Turn Your Hacking Skills Into a Career  - Orson Mosley, Naz Markuta, Tom Kranz
    • As hackers, we all have unique skills and abilities that are in huge demand globally.  But cybersecurity can be a tough industry to break into, and the acronym soup of qualifications and certifications can make it difficult to work out how to get started.
    • Orson, Naz, and Tom will present a discussion panel on how to build a successful career in cybersecurity from a background in hacking.  All three have very different, diverse backgrounds, and very different skill sets - yet have managed to bypass university degrees and build their own unique careers in the industry.
    • Anyone who wants to break into the industry, who wants to further their career, or just wants to understand how to use their passion to pay the bills will benefit from attending this panel.  Tom is now a CISO, published author, and consulting director.  Orson and Naz have taken very different routes in their careers, but are now highly regarded security researchers at an award winning cybersecurity consultancy in the U.K., presenting their research to industry leaders and executives.
    • There isn't a shortage of cybersecurity skills in this industry - there's a shortage of people with the right attitudes and motivations.  This panel will share their experiences - both good and bad, as well as the personal issues they each overcame - and encourage and enable others from equally diverse backgrounds to build their own unique careers in the industry.

  54. (2020)  How Your Mobile Phone Is Tracking You - and How to Fight Back  - TProphet
    • Most people know that the government can track you via cell site location and E911 data, and that social networks have extensive location tracking capabilities.  However, fewer people are familiar with the shadowy world of location tracking via data brokers and apps.  Learn how simply giving a business your mobile phone number can be construed as "consenting" to them electronically following you like a creepy stalker, 24-hours-a-day, 7-days-a-week.  We'll also go over some creative ways to take back your privacy while still enjoying the convenience of a mobile phone.

  55. (2020)  Hunting Bugs in Your Sleep - How to Fuzz (Almost) Anything With AFL/AFL++  - vr0n
    • This is a "part one" talk on exploitation detailing how to get started with AFL to find bugs (usually memory corruption vulnerabilities).  Finding bugs in a program gives you the opportunity to research further potential vulnerabilities and exploitation.  It's really that simple.  vr0n will show how to install AFL, how to set up AFL, and how to use AFL against a program.

  56. (2020)  Hybrid Attacks - Becoming the Stainless Steel Rat  - Eric Michaud
    • In our dystopian present, the digital world is enmeshed with the physical.  Security controls once made of steel are turning into silicon and copper wire.  Door locks are being replaced by key card access, car keys replaced by electronic fobs, and "wallets" are digital files which store your cryptocurrency.  Subsequently, real world operations now often contain both physical and electronic components.  This talk will cover why the current landscape exists, and the implications for offense and defense.
    • From heisting cars to stealing Bitcoin, this talk will dive into real hybrid attacks which blend lockpicking and hacking, physical bypass and digital access.  You'll understand why the hacker needs to know how to pick locks, and why the Wi-Fi Pineapple and USB Rubber Ducky are becoming part of the physical access specialist's toolkit.
    • "It was easier in the old days... just as old wooden buildings have more rats than concrete buildings...  Now that society is all ferrocrete and stainless steel there are fewer gaps in the joints.  It takes a very smart rat indeed to find these openings.  Only a stainless steel rat can be at home in this environment..." - Harry Harrison, The Stainless Steel Rat

  57. (2020)  Inside Job: Exploiting Alarm Systems and the People Who Monitor Them  - Nicholas Koch
    • Alarm systems are a staple of businesses nationwide.  When you walk into a building, the door contact separates, making the alarm panel chime.  The motion detector sees you... but what about what you don't see?  The person in the central station getting a ping and looking at the signals, calling the owner, then the police.  This talk covers the basic types of alarms, common panels, and central station procedures, as well as how to exploit them and what you can do to help mitigate these exploits.

  58. (2020)  Introducing *DAS: A Framework for Certifying Hacker Knowledge  - Dana Gretton
    • Hacker knowledge is open to all, community-backed, and defies regulation.  All education could be enhanced by these unique strengths, but they also represent challenges: How can we build trust in excellent hacker knowledge sharing?  How can we start to style all education after hacker learning, while maintaining the level of trust people place in certificates and transcripts?
    • This talk introduces the Reference-Rich Decentralized Accreditation System (DAS), a conceptual framework and developing circle of open-source software for certifying knowledge among learners and between far-flung learning communities.  Dana will show how the tech backing DAS aligns learners' incentives to certify each other and themselves by offering statistical inference that reveals excellent teaching.  He will describe high school pilot studies by makerspace learner-teachers in Beijing's Moonshot Academy as example applications.  Dana will also demo how to use DAS to evaluate some of our own learning about other topics, like cooking and programming.  DAS does not use machine learning and it prioritizes data privacy.  The DAS concept is designed to democratize education, lessen systemic inequality, and reward exponentially spreading peer-to-peer teaching and learning.

  59. (2020)  Introduction to Locksmithing  - The 703 Locksport Crew
    • Many "hacker"/infosec conferences have talks and workshops that cover lockpicking.  However, the adjacent skills of locksmithing remain underexplored.  This talk/demo seeks to focus on the following topics:
      • Explanation of basic locksmithing tools (re-pinning kit, plug followers, calipers, etc.)
      • Identifying key blanks and decoding keys
      • Disassembling locks
      • Changing out pins to work with a different key
    • These skills will be useful for a variety of audiences: locksport people looking for increased knowledge of lock operation, locksport people interested in constructing challenge locks, as well as homeowners interested in doing their own lock re-keying.

  60. (2020)  Intro to Game Hacking on the NES  - leethacks, stakfallt
    • The Nintendo Entertainment System features the Motorola 6502 CPU.  This presentation serves as an introduction to the 6502 instruction set and features an overview of how the Game Genie works, memory hacks, and how to use techniques like write-breakpointing to further analyze and edit instructions.  Free/open tools such as Bizhawk and FCEUX will be utilized.

  61. (2020)  IRREGULATORS v FCC: The Trillion Dollar Broadband and Accounting Scandal  - Bruce Kushnick
    • In 2018, Bruce presented a HOPE talk on how America was supposed to be a fiber optic nation where the telecom pipes were supposed to be open to all forms of competition.  Customers paid over half a trillion dollars to make this happen by 2018 - and that was the low number.  Through mergers and the takeover of the FCC and some state commissions, today there are only a few companies that have taken control of most of America's broadband, Internet, cable TV, phone, satellite, and wireless services.
    • But in 2019, the IRREGULATORS took the FCC to court because they uncovered that AT&T, Verizon, and the other companies had been able to manipulate the very accounting formulas: they made the entire U.S. infrastructure appear to lose money so that they could not only leave whole areas of America to deteriorate, but could inflate all prices, included wireless - adding another half a trillion dollars in overcharging since 2000 and continuing to the present unabated.
    • In 2020, they got the decision they wanted: The states are independent from the FCC's manipulated accounting.  Net neutrality and the digital divide can now be fixed, we can get back our privacy and stop the overcharging, and we can finally get gig speeds and open pipes.  We can hold them accountable for their misdeeds and take the final step.  It's time to break up AT&T, Verizon, and the cable companies... again.

  62. (2020)  iWar and Information Warfare, the Next Phase of Internet Motility: Manipulation Inherent to the Internet's DNA  - Alexander Urbelis, Roel Schouwenberg, Daniel Nowak
    • Information warfare, disinformation, and propaganda have persisted since the beginning of recorded history.  Much like many of the world's oldest professions (espionage and sex work), information warfare has come under a variety of names and agendas.  And much like espionage and sex work, information warfare remains alive and well in the present day.
    • From the old world where we have Asurbanipal's clay tablets relating elaborate tales of "glorious" military victories to Bernays's ushering in the modern era dominated by 20th century multi-modal propaganda campaigns, this talk will delve into a history of the sordid concept known as infowar.  The panel will examine the pre-history of disinformation, iWar, misinformation and propaganda, all through both an historical and technical lens.  They will address the advent of the printing press, moving swiftly to WordPress and the Dark Net.
    • With respect to our present predicament in 2020, rather than clay tablets and cuneiform, we have dysfunctional social media systems, broken identity management concepts, multi-national troll farms, and a profusion of Internet-connected systems, all of which adversaries with malicious intent routinely manipulate.  The concept of the Internet being used as an information warfare domain was not a twinkle in the eyes of inventors of the packet switched system that became known as ARPANET.  The Internet was designed for functionality, not security, and therefore remains insecure.  Trust and the integrity of information is still an issue 60 some years after the first proof of concepts reared their head at the RAND corporation.
    • This talk will address the challenges surrounding information warfare management, the intersection of infowar and iWar, as well as methods for identifying and inoculating against the strategies and tactics of 21st century iWar/PSYWAR operators.  It will reference recent examples of state-sponsored activities, coronavirus-related activity in the DNS, and will look ahead to the 2020 election and beyond.

  63. (2020)  Keynote: Cindy Cohn  - Cindy Cohn
    • The digital rights movement started with the founding of EFF 30 years ago this summer.  Let's take stock of where we are, what we've accomplished, which fights are still ongoing, and which are currently red hot (looking at your encryption).  But then let's talk about where we go from here.  We can only build a better future if we can imagine it, so how do we take what we've learned from the last 30 years - our successes and failures - and apply it today so that in the next 30 years we can honestly say that technology supports freedom, justice, and innovation for all the people of the world.

      

  64. (2020)  Keynote: Cory Doctorow  - Cory Doctorow
    • We Used to Have Cake, Now We've Barely Got Icing
    • When free software licensing was born, software copyrights were essentially nonexistent, software patents didn't exist at all, terms of service weren't enforceable and there was no anti-circumvention law.  In other words, you were legally permitted to clone or interoperate with any digital product.  Today, we think of free software as a way for a company to say, "We probably won't sue you if you write code that can interoperate with ours" - but when free software started, it was more like, "I know I've got the absolute legal right to reverse engineer all your code and make a competing product, but that's such tedious work.  Please, make it easy for me by giving me your source code."  Back then, free software was icing on the cake.  Then they stole the cake and left us hoping for a little icing every now and then.
    • This makes a huge difference because software has eaten the world and shit out a dystopia: a place where Abbot Labs uses copyright claims to stop people with diabetes from taking control over their insulin dispensing and where BMW is providing seat-heaters as an-over-the-air upgrade that you have to pay for by the month.  Companies have tried this bullshit since the year dot, but Thomas Edison couldn't send a patent enforcer to your house to make sure you honored the license agreement on your cylinder by only playing it on an Edison phonograph.  Today, digital systems offer perfect enforcement for the pettiest, most jewiest, greediest grifts imaginable.

  65. (2020)  Keynote: Flavio Aggio  - Flavio Aggio
    • COVID-19 Cybersecurity Attacks
    • Cybersecurity technologies to identify, protect, detect, respond, and recover are extremely important, but not sufficient.  HumanOS upgrade is required to safely use the Internet and it is not only about training and awareness.  It is about the way users must behave online.  The IT community must openly acknowledge system vulnerabilities.  Humans are the weakest and strongest links in cybersecurity.

  66. (2020)  Keynote: Idalin Bobé  - Idalin Bobé

  67. (2020)  Keynote: Jaron Lanier  - Jaron Lanier

  68. (2020)  Keynote: Libby Liu  - Libby Liu

  69. (2020)  Keynote: Richard Thieme  - Richard Thieme
    • Now More Than Ever: The Hacker Revolution Meets the Pandemic
    • A quarter century ago, Richard began addressing the impacts of the hacker revolution on the human inside the machine - how it would transform our lives, our thinking, our work, our identities.  He was describing the "digital revolution" as a transformational engine, not as an academic exercise, but as genuine paradigm change.  He was called "crazy" and "insane" but it all came to be as he described: hackers created the frames in which others lived - inside the bigger picture without even knowing it.  Insanity, like wisdom, is apparently contextual.
    • The pandemic is creating another paradigm change which asks that we apply real hacker methodologies to new realities.  Context matters, and the context is the content of our lives.  Hackers have the tools to identify the fragments of a disintegrating society and use them to model new structures.  Hackers have internalized procedures, assumptions, and working models to piece together parts of complex systems to create new wholes, to break down to break through.  Hackers once again are thought leaders for a brave new world.
    • Leadership that is conscious and intentional puts the reins into our hands.  This talk will illuminate how we need to apply our expertise to create a new landscape, how the "hacker ethos" translates into practical action.  Because, as Philip K. Dick said, "Reality won't go away just because we refuse to believe in it."

  70. (2020)  Keynote: Tiffany Rad  - Tiffany Rad
    • As the daughter of a former case officer, Tiffany's father taught her about electronic and physical security at an early age.  (He had a lockpick set that rolled out of a canvas case and looked like a surgeon's precision tools.)  She grew up hearing stories about "sneaks," as he called them, where he would be hired as a consultant to "break into places so bad people could not break into places."  After a successful sneak (and they all were - never a failure), he designed better security for the facility.  Later on, he contributed to the movie, Sneakers.
    • A few years later when she was in college, Tiffany met computer engineers who introduced her to computer hacking.  This is where she learned about Kevin Mitnick's arrest and subsequent conviction.  She was so intrigued about his case that she went to law school.  She discovered there was a need for attorneys with technical expertise.  Years later, she started working with her father on consulting projects.  In 2011, she simulated a prison break (in the safety of a sandboxed environment in a basement in Virginia) by finding and exploiting vulnerabilities in industrial control systems.
    • Now, Tiffany accesses car computers and works to protect transportation and critical infrastructure.  She'll be talking to you about some of her other inspirations - including vehicle tuners, hot rodders, and rally racers (the first car hackers) - and how it's important that we maintain the ability to use, buy, and create tools that allow us to access systems and devices for assessment and modification.
    • More than ever, who controls the code - from a legal and technical perspective - will determine if we are simply "users" of our devices or "owners."  And from a vehicle research perspective, are you a "driver" or are you "driven?"

  71. (2020)  Keynote: Yeshimabeit Milner  - Yeshimabeit Milner

  72. (2020)  Launching the Cyrillic IDN TLD as the first Internationalized Domain Name in the World  - Dr. Yulia Ovchinnikova
    • This talk will cover the birth of the Russian domain space (.ru), its evolution, and how it addressed challenges such as creating/managing non-Latin international domain names (IDN) starting with the first Cyrillic domain (a pioneering ICANN program) and de-monopolization of the Russian domain business while educating government officials.

  73. (2020)  Let's Have a Board Level Talk (i.e., Hardware Interface Boards)  - Bruce Barnett
    • This talk provides an introduction and survey of existing and future boards used to interface and reverse engineer electronic equipment.  These are boards that allow your computer to interface to the protocols used in embedded computers, such as UART, I2C, SPI and JTAG, and SWD.
    • If you want to know more about these boards, what they can do, and how to use them, this is a good introduction.  There are over 20 products and designs, such as the BusPirate, Facedancer, GreatFet, JTAGulator, Shikra, Focaccia, Shukran, the Black Magic Probe, etc.  In addition, developers are working on the next generation, such as the Luna, BusPirate Ultra, Glasgow, and Edinburgh boards.  If you don't know what to buy, or the advantages and disadvantages of each, this talk will help clear things up.

  74. (2020)  Librarians and Crisis Response: The Case of COVID-19 Maker Response  - Alex Gil, Madiha Choksi, Moacir P. de Sá Pereira
    • On Thursday, March 19, 2020, Dr. Pierre Elias, a Columbia University cardiology fellow, reached out to Research and Learning Technologies librarian Madiha Choksi to utilize the Columbia University Libraries' 3D printers to produce supplemental face shields.  Within a few days, she had optimized an existing design for face shields, taken two 3D printers from Butler Library to her apartment, and was printing parts and assembling shields.  A few days later, she was joined by her fellow librarians, Alex Gil and Moacir P. de Sá Pereira.  Two months later this team of librarians had organized one of the largest PPE grassroots efforts in the city, COVID Maker Response, which effectively produced and distributed more than 25,000 face shields to New York City hospitals and other front line institutions during the height of the city's pandemic crisis.
    • In this talk, the three librarians will share their experience building this volunteer collective: logistics, finances, project management, and communications.  The team will also expand on their notion of "nimble tents" - a trans-institutional approach to rapid hacking in moments of crisis - and recent experiences and examples, including the #PRMapathon library response that effectively rebuilt the OpenStreetMap of Puerto Rico after Hurricane Maria to help the Red Cross, and the rapid response research of illegal alien problem of 2018.  At the core of the librarians' argument is the idea that library professionals already have the skills they need to make effective and impactful interventions in moments of crisis.

  75. (2020)  Lightning Talks #1   -
    • Lightning talks return to HOPE!  Do you have something interesting to share with other attendees?  Lightning talks allot five minutes per presenter on any topic within the broad scope of HOPE interests.  Registration details will be announced during HOPE, and scheduling will be done during the conference.  Presenters will join a live teleconference, and may share up to five slides in the five minutes allotted.

  76. (2020)  Makerspaces Hacking the Space Industry by Enabling Effective Cross-Industry Collaboration and Enhancing the Space Workforce Development  - Nancy C. Wolfson
    • "Space belongs to all," we often hear.  However, most people do not relate their lives to space.  The Outer Space Treaty was signed on 27 January 1967.  Article I of the Space Treaty says "The exploration and use of outer space including the Moon and other Celestial Bodies, shall be carried out for the benefit and in the interests of all countries, irrespective of their degree of economic or scientific development, and shall be the province of all mankind."
    • Most people know space through news, stories, and entertainment.  Some might know that space technology is making their lives easier, but they would not consider themselves able to contribute in any way.  At the same time, the space community has remained mostly among itself.  This presentation will argue that it is the responsibility of the space specialists to create new partnerships and collaborative projects that connect space and non-space actors and explore new nontraditional academic models and environments that can ignite creativity and foster cross-industry collaboration.
    • The global crisis due to China COVID-19 has somehow forced us to rethink how we could take cross-industry communication and collaboration to the next level.  Some tips and tricks will be shared to continue with cross-industry collaborative projects utilizing digital and online technology.  Makerspaces' tech knowledge transfer model can enhance the space workforce development and lead to innovative research and inspire the next generation inside and outside the space community.

  77. (2020)  Meet the EFA: A Discussion on Grassroots Organizing for Digital Privacy, Security, Free Expression, Creativity, and Access to Knowledge  - nash, Abi Hassen, Emilie St-Pierre, Elliot, Freddy Martinez
    • Founded by the Electronic Frontier Foundation (EFF), the Electronic Frontier Alliance (EFA) is a grassroots network of community and campus organizations across the United States.  Join representatives from the EFF, and EFA affiliated groups, for this panel discussion on community-based tech advocacy, and working within your community to educate and empower neighbors in the fight for data privacy and digital rights.

  78. (2020)  Mobile First Digital Identities and Your Privacy  - Alexis Hancock
    • "Mobile First" is more than a web developer's mantra chanted from 2010.  It also means that many people now visit websites and use services from their mobile devices more than on laptops and desktops.  Recently, several proposals and published models for establishing big parts of our lives through our mobile devices have been discussed.  Big proposals include mobile driver's licenses, mobile health credentials, and other forms of digitized documentation such as university degrees.  Recently published and proposed standards include the W3C's verifiable credentials data model and the ISO's 18013-5 mobile driver's license compliance.  This talk discusses the privacy concerns that surround these ideas, test cases, and the trajectory of digitized identification.
    • The aspirations of these technologies are utopian.  However, we are in a reality that makes digital identities subject to centralized power structures.  Crafting who we are online can look different if these technologies become standard in our everyday interactions, especially if these interactions include employers and health care.  These scenarios affect the most vulnerable among us, the people who don't get the chance of anonymity online.  Engaging in these conversations helps bring to light concerns that may not be considered, and helps to craft a better digital future.

  79. (2020)  No One Can Predict the Future  - Xiaowei Wang
    • This talk is about the rural-urban connections of tech in the Chinese countryside, and the impacts of tech on rural areas that are increasingly globalized.  Xiaowei will tell the story of their visit to a police station in the city of Guizhou, and how they talked to a police officer about the implementation of their "Real Population Platform," a platform designed to surveil rural migrants in the city.  A visit to the offices of Face++/Megvii, which makes face recognition algorithms for China's Skynet surveillance system, will also be described.  Through this research, they look at the realities of how these platforms and algorithms are used on the ground (along with implementation challenges, from data quality to collection, and the global profiting on surveillance).
    • This talk seeks to open up a broader discussion on data, representation, and the ethical and philosophical questions surrounding prediction as an industry built by tech.  As the police officer in Guizhou said, "no one can predict the future."  So why do predictive policing platforms still exist?  What is the circular logic that remains in engineering?  What are the potential strategies and areas of countering these types of surveillance?

  80. (2020)  On Computational Law: Why the History of Computing Could Be the Future of Law  - Meng Weng Wong
    • The government of Singapore recently bet ten million dollars on a research program to develop an open-source domain-specific language - for law.  This talk explains why, and introduces lesser-known corners of computer science (like formal methods, controlled natural languages, and logic and constraint programming) and suggests that together they could permanently divide the traditional legal profession (which runs on humans) from a future legal industry (which runs on computers).
    • This talk offers a quick tour of useful theory that every self-taught hacker should be acquainted with, and shows how they solve problems in law.  Lesser known chapters from the history of computing will be examined, such as formal verification, the temporal logics LTL and CTL, decision tables, DSLs, constraint satisfaction, and model checking, as well as strongly-typed languages for natural language generation.  You will see how Knowledge Representation and Reasoning (KRR) could move out of the heads of lawyers and into a computer.  This talk outlines a plan for a domain-specific language for law, following the ethos of open-source and open-standards that promises to make it possible for hackers, consumers, and non-lawyers to get certain legal jobs done by themselves - not by going to a law firm, but by going to GitHub.

  81. (2020)  On Doing Good Enough  - Mek
    • We're facing pretty difficult times and many in our communities are struggling.  China COVID-19, unemployment, racial inequality, turbulent politics, and the psychological stresses of shelter-in-place all conspire to form a perfect storm.  If there is a silver lining, it's that there too are a multitude of opportunities for us to help each other, to share resources, and to use our hacks for good.  It's hard knowing where to start, it's hard to get started, and it's hard to keep going.
    • As technologists, many of us are uniquely positioned to do work remotely and collaborate.  This talk will describe how to use this to our advantage.  Whether you're out of work and need help, you're trying to stay employed and avoid burnout and distractions, or you have extra bandwidth and are looking for ways to "fight for the user," Mek will show how to share resources, techniques, and opportunities which hopefully will help each of us do good enough, together.

  82. (2020)  One Ring to Surveil Them All: Hacking Amazon Ring to Map Neighborhood Surveillance  - Dan Calacci
    • The wealthiest company on earth now controls one of the U.S.'s most pervasive and complete video surveillance networks of public space, marketed as a personal and community safety tool: Amazon Ring.  These doorbell cameras record public streets all day, every day, and make footage available to local law enforcement through partnerships with over 900 police departments.  With no legal protections in place to ensure responsible stewardship or governance of such a network, understanding its breadth and extent is crucial.  Amazon Ring includes a membership to a neighborhood "surveillance social network" called Ring Neighbors, where users post recorded videos and other content, in the name of public safety.
    • In 2019, Dan reverse engineered the private API that Amazon Ring uses to communicate with its mobile app, and developed a methodology to systematically scrape every post on the Neighbors app throughout the U.S. since the beginning of 2017, including posted videos.  In this talk, they detail how they reverse engineered the API, how activist hacking can help us track and hold companies like Amazon accountable, and what the data has been used for so far: mapping Amazon's growing surveillance network, using statistical methods to understand who uses the platform and why, what kinds of people Ring users find "suspicious," and other adventures.

  83. (2020)  OSINT of Facilities by Physical Reconnaissance  - Bill Graydon
    • When hacking a physical facility, intelligence is key.  Knowing the internal layout of a building will assist in identifying and accessing targets as efficiently as possible and anticipating security measures.  In addition, for effective social engineering, it helps to know where you're going.  This talk will focus on inferring what is inside a building just by looking at the outside: what is the layout of the hallways, where are the stairwells and elevators, where are what rooms?  Bill will introduce a methodology for deducing the floor plan of a building from observing its external envelope, which is the result of years of research into thousands of architectural plans for a wide range of facilities.
    • Also outlined will be loads of techniques for situational awareness and intelligence gathering when navigating through a building.  The implications for physical red teams and for facility managers to harden their operational security against these techniques being used by bad actors will be examined.  This talk focuses on low-tech techniques, most involving only the human senses.  Attendees will come away from the talk with a new perspective on the built world around them, and will be able to apply it in all urban aspects of their day-to-day lives.

  84. (2020)  People Are Not Bots - or How Researchers Delegitimize Social Movements  - Michael Kreil
    • At first, it didn't sound wrong.  Scientists were going to track down social bots using scientific methods in order to study their influence on public debates.  But a deeper look into the research shows that it is anything but scientific.
    • Researchers work with wrong claims and flawed methods.  Algorithms, instead of being open-source, are intransparent.  Results contradict each other.  Papers have been rejected by scientific journals.  To this day, nobody has been able to present any scientific proof of "mass manipulation by social bots."
    • Yet this narrative is strong enough to delegitimize major political movements like Fridays for Future or Black Lives Matter.  When scientists claim that a movement consists of bots, its voices are less likely to be heard.
    • It is time to set the record straight: People are not bots!

  85. (2020)  Pick Better Fights With Your Boss  - Nada O'Neal
    • There's nothing worse than being right all the time, but having no power to persuade or make change.  In this talk, Nada will show you how to talk to the suits in your work life, first about mundane matters like software purchases and info security, and then about what we really care about: violations of equity or rights.  Learn how to meet them where they're at to bring them onto the right path.

  86. (2020)  Polygraph "Tests" and How to Beat Them  - George Maschke
    • Polygraph or "lie detector" testing has long been discredited from a scientific standpoint.  Yet it has been embraced by the United States government for decades, and in 2020 it is the centerpiece of American counterintelligence policy.
    • Employees and contractors of such agencies as the CIA, NSA, FBI, and numerous others are required to undergo pre-employment and recurring polygraph screening.  Yet there is no documented instance of routine polygraph screening ever catching a spy.
    • This talk will address how this state of affairs came to be.  It will further address polygraphy's scientific shortcomings and why it poses a threat to innocent test takers, and it will explain proven strategies for passing (or beating) a polygraph "test."
    • The talk will also address the U.S. government's recent efforts to suppress the teaching of methods for fooling the polygraph.
    • This topic will be of particular interest to the hacker community because many information technology jobs with the U.S. government and its contractors require that the applicant submit to polygraph screening.

  87. (2020)  PolySense: Reverse Engineering Flex Sensors, and Destroying Your Kitchen With Chemistry for Electrical Functionalization of Everyday Objects  - Cedric Honnet
    • PolySense is a fabrication process that adds electrical functionality to various materials.  Using this method, you can, for example, create clothes which measure your body movement, or gloves which heat your hands.  PolySense might find application in VR by creating thin, breathable gloves with precise motion tracking abilities, or in dance performances by creating elastic, moving clothing which might also control light and sound.  All of this is based on fabric augmentation, using tools you can find in any kitchen.

  88. (2020)  Portal to Tesla's Wardenclyffe Lab  - Marc Alessi
    • Explore the wonders of Wardenclyffe, the historic laboratory built by science visionary Nikola Tesla, where he engineered a colossal 18-story wireless transmitting tower and conducted experiments that still evoke questions and controversy over a hundred years later.  Presenter Marc Alessi, executive director at Tesla Science Center at Wardenclyffe, will share past, present, and future happenings at the site, including details on a recent discovery made during renovations and fascinating info on the tunnels beneath Tesla's legendary laboratory.  You'll see actual experiments in wireless tech using Tesla coils along with a surprising electric music performance.  You can further satisfy your curiosity during the live Q&A session.

  89. (2020)  Power to the People: Effective Advocacy for Privacy and Security  - Aelon Porat
    • Whenever a co-worker's password is cracked or someone's intimate pictures are plastered online, we roll our eyes and laugh at the idiot.  We lose patience when the commoners don't understand the implications of search engine companies diversifying into home automation and genetic testing.  We still can't effectively articulate the importance of being vigilant to non-techies.  Why shouldn't someone use Windows XP or plug-and-play security cameras in their bedroom?  After all, they've got nothing to hide and the old OS works just fine.
    • Our community is generally unsuccessful in promoting privacy and security to ordinary people.  This talk will discuss common advocacy pitfalls and present effective training ideas that convey to non-techy folks the long-term importance of privacy and security.
    • For example, an app will be introduced that exposes extremely personal details on its users after it's given basic phone permissions.  Regular users get to see intimate conclusions about their lives piled up on the server screen in real time, creating a unique profile as the innocent game they installed mines every byte of their data.  Aelon will discuss the financial incentives around this, showing how users' profiles can be sold to data brokerages.  There will be a demonstration of modern apps that may prolong screen time by displaying targeted, emotionally-engaging content when detecting that the user is about to leave.  We will see how our brains react to certain stimuli which tech products can exploit to further hook users.
    • A phishing link will be demonstrated as it takes over a user's laptop.  Databases of scattered consumer security cameras will be inspected to explore how unintended, yet fully-automated and efficient mass surveillance systems are created.  This presentation will review some of the ways PIs track down a subject across the country and share other eye-opening demonstrations.
    • The talk will discuss where other conscientious techies can help with triggering meaningful discussions and opening the average person's eyes to the realities of tech in the 2020s.

  90. (2020)  Practical Solutions for Internet Routing Security and DDoS Mitigation  - Dr. Olaf Kolkman, Dr. Kotikalapudi Sriram
    • This talk will review a range of solutions for Internet routing security and distributed denial-of-service (DDoS) mitigation.  The solution methods include RPKI, Route Origin Validation (ROV), BGP signaling for mitigation of route leaks, Enhanced Feasible-Path Unicast Reverse Path Filtering (EFP-uRPF), Remotely Triggered Black Hole (RTBH) filtering, and Flowspec.  These techniques are covered in detail and security guidance is also offered in NIST Special Publication 800-189.

  91. (2020)  Pricing and Mapping the Underground Economy: An Analysis of Contracts on the Biggest Online Hacking Forum  - David Hétu
    • Hackforums is known as the script kiddie forum of hacking where most up and coming hackers drift to.  Past investigations have shown, however, that many established hackers are still very much active on the platform and use it to transact illicit goods and services.  This presentation builds on the contract section of the forum that has archives going back over one year.  This contract section provides detailed information on the transactions that hackers have negotiated over Hackforums.  Using tens of thousands of contracts scraped from Hackforums, David will provide an analysis of the true cost of hacking tools and services, not those advertised publicly on the forum.  He will conduct social network analysis of the actors involved in the transaction of illicit goods and services to identify key players and map the structure of the social organization of the illicit trades facilitated by Hackforums.  This presentation will provide new and solid evidence of the inner workings of the underground illicit economy, as well as provide a methodology to identify key players in hacker networks based on the best practices of the social network analysis field.

  92. (2020)  Principles of Digital Autonomy  - Karen Sandler, Molly de Blanc
    • We have rights with respect to our technology.  These rights are imperative to ensuring our digital autonomy: our right to be in control of our own destinies.  As the border between the physical and the digital breaks down, it is increasingly becoming necessary to reexamine what we consider to be the rights that protect our digital autonomy, and the way those abstract ideas apply to existing (and theoretical) technology.
    • Cyborg lawyer Karen Sandler and digital rights activist Molly de Blanc will first discuss the principles of digital autonomy, clarifying what your rights are and the principles that define them.  They will then analyze popular technologies including video chat software in the context of these principles.
    • Karen and Molly wrote the Principles of Digital Autonomy to summarize what they have learned in their time as digital rights advocates and activists.  In this session, they will share them with the audience and then look at software and hardware, including Zoom, from the lens of those principles.

  93. (2020)  ProjectMF 2.0 with NPSTN  - Dylan Cruz
    • ProjectMF was originally started by Phiber Optik in 2006.  ProjectMF 2.0 is an adapted version that is compatible with the latest versions of Asterisk (an open-source telephony toolkit), compatible on all hardware with no software recompilation or hardware modifications.  It is a self-contained piece of software using bandpass filters and level gates to ensure it works 100 percent of the time.  ProjectMF 2.0 is a piece of software that, when combined with Asterisk, can allow MF signaling, ACTS signaling for payphones, 2600 supervision, and SF signaling.  It is able to detect OSPS tones like ringback, coin collect/return, and finally and very impressively, it is able to decode rotary phone pulsedialing sounds!  So you can use a rotary phone on any VoIP ATA or channel bank in the world!  This gives anyone access to rotary phones on any piece of equipment!  It even allows rotary phones on POTS lines to navigate your Asterisk IVR!
    • When you couple all of this with the open-source NPSTN phone network (npstn.us - a VoIP phone network for telephone phreaks, collectors, professionals, and hobbyists), then something great happens.  All of a sudden, you can dial a number, and MF will come on the line and signal in real time to the remote switch.  Once the call is connected, you can do crazy stuff like Blue Boxing on the trunk.  You can literally flash your switch hook and cause a reset on the "circuit."
    • NPSTN also has real live operators in a handful of countries across the world.  They have around 40 active members and switches on the network.  They have ACTS coin-trunks, real crossbar and step switches, and any type of signaling used on the phone network of the 1970s that you can imagine!  You can easily move from an intercept message to a secret party-line conference.  NPSTN is truly the best "simulation" of the old phone network.
    • This talk will give you a thorough tour of the magic of ProjectMF 2.0, NPSTN, and the world of phone phreaks, past, present, and future.

  94. (2020)  Quantum Encryption  - Robin Wilton
    • Every so often we see another headline announcing a major breakthrough in quantum computing, often accompanied by breathless warnings of the death of encryption as we know it.  How real are these claims?  Is encryption really doomed?  How is quantum computing a threat anyway, and is there anything we can do about it?
    • This is a session for people who are IT literate but not physicists, let alone quantum physicists.  Come along if you’d like to hear quantum computing and encryption explained by someone who is IT literate, but not a physicist, let alone a quantum physicist!

  95. (2020)  Qubes OS for Organizational Security Auditing  - Harlo Holmes
    • Many members of the international Internet freedom community perform organizational security audits for non-profits, media organizations, and small NGOs in need.  These services are by no means full-fledged penetration tests, but they effectively respond to a specific need for affordable and achievable ways to bolster a small and cash-strapped organization's security posture.
    • While different OrgSec auditors may have their own tooling, Harlo will introduce you to the workflow developed at Freedom of the Press Foundation, centered around the Qubes operating system.  This session will cover compartmentalization, building custom environments with powerful penetration testing tools, observing network activity without contaminating your results with personal traffic, working with peripherals like external Wi-Fi cards and network taps, and even air-gapped and confidential report generation.  Oh, and since we are in the midst of a global health crisis, she'll address how some of this work extends well (or not-so-well) to a strictly remote practice.  Throughout the session, Harlo will demonstrate how certain modules within popular auditing frameworks, like the SAFETAG methodology, are made all the easier and effective by taking advantage of the great set of features available in a Qubes workstation.
    • The goal of the session is to bridge the gaps between popular auditing techniques and their actual practical implementation.  This will also be a great opportunity to discuss with the HOPE community the finer philosophical goals and methodologies that have been built around OrgSec auditing at a smaller scale, while showcasing how a pretty nimble setup using this new and exciting operating system has been created.

  96. (2020)  Reform or Expire?  The Battle to Reauthorize FISA Programs  - India McKinney, Andrew Crocker
    • On March 15, 2020, Section 215 of the PATRIOT Act - a surveillance law with a rich history of government overreach and abuse - expired.  Along with two other PATRIOT Act provisions, Section 215 lapsed after lawmakers failed to reach an agreement on a broader set of reforms to the Foreign Intelligence Surveillance Act (FISA).
    • In the week before the law expired, the House of Representatives passed the USA FREEDOM Reauthorization Act, which would have extended Section 215 for three more years, along with some modest reforms.  After negotiations, the Senate passed a slightly amended version of the bill, but after a veto threat from the President, the House of Representatives failed to pass it.  The bill currently remains expired, but the question remains - for how long?  And what will reform look like?
    • In this discussion, India and Andrew will explain the political factors behind this unusual legislative journey, as well as the policy implications of these proposals.

  97. (2020)  Resistance to NSA-Level Global Adversaries With the Nym MixNet  - Ania Piotrowska
    • Anonymous communication networks, such as Tor, are vital to maintain our privacy against adversaries that can monitor our network traffic to collect metadata like IP addresses.  However, Tor does not defend against global passive adversaries that can observe the input and output of the entire network, such as all the traffic going in and out of Tor entry and exit nodes.  For message-based systems, it has been shown that mix networks that reorder (mix) packets can defend against these nation-state level adversaries.  After years of research as part of the European Commission PANORAMIX project and one year of coding, the Nym project has launched its generic, Rust-based MixNet code.  This talk will demonstrate how a mix network can eliminate even timing information from a chat application, and how developers can build on top of this new mix networking framework.

  98. (2020)  RFC 1984 - or Why You Should Start Worrying About Encryption Backdoors and Mass Data Collection  - Esther Payne
    • How do we slay the Hydra of mass surveillance?
    • We live in a time where citizens put data into commercial, health care, and government systems to access services.  Some services are only accessible online.  From CCTV to Facebook, people have little understanding of why mass collection of data is dangerous.  So once we disquiet everyone about this, what do we do next?
    • In many ways, mass data collection and surveillance devices much like the Lernaean Hydra keep springing back.  Public pressure on individuals who championed Google Glass only lasted for so long.  We have similar issues with Amazon Ring and to some extent Facebook.  How do we get people to consider not buying devices like Amazon Ring?  While calling people glassholes was effective, times have changed along with presidents.  The world is polarized and we need to reach across the divide to persuade.
    • How do we engage people outside our tech bubble and encourage them to engage with organizations like the ACLU and help us to put pressure on our elected representatives?  How do we cauterize the head of rampant facial recognition technologies and then do the same for the heads of shadow profiles, DNA profiles etc.?
    • RFC 1984 was explicitly named to reference an Orwellian society that uses mass surveillance.  This talk will seek to expand that beyond encryption to the mass collection of data and ask how do we limit this?  How do we limit access to this data?  How do we stop the nightmare?

  99. (2020)  Ring's Wrongs: Surveillance Capitalism, Law Enforcement Contracts, and User Tracking  - Bill Budington
    • Throughout the last few years, the Ring smart doorbell has been purchased by many residents with the idea that it will keep their homes safer.  But Ring, the company owned by Amazon that produces the Ring doorbell, does a lot more than simply monitor your home for you.  It has forged secretive partnerships with over 1300 law enforcement agencies across the country, providing them with unprecedented access to footage across American communities, and often even inside the home.  At the same time, Ring has been lackluster in its approach to product security, leading to a number of high-profile breaches giving hackers access to video streams and allowing them to use the doorbell's speaker to harass an eight-year-old child inside her home.  Finally, original research conducted by EFF has shown the Ring app to be packed with third-party tracking libraries, sending a huge amount of information on customers' devices and habits to tracking companies without disclosing to users that this was happening.
    • This talk is going to catalogue Ring's Wrongs and EFF's campaign against these practices - practices that not only facilitate the overreach of law enforcement and injure user privacy, but also provide the clearest example of surveillance capitalism, a new frontier of profiteering.

  100. (2020)  Saving Hacking From the Zaibatsus: A Memoir  - The Gibson, The Doctor, Kirk Strauser, R¥, Alice Rhodes (c0debabe)
    • Your data is not theirs to own.
    • With the advent of centralized social networks in the mid-2000s, all culture became consumed by the giants.  Those giants then proceeded to sell your information, your privacy, and even our nations.  Yet they still trudge on, much like John Perry Barlow's weary giants of flesh and steel, and we do little to stop them.
    • Your data is not theirs to own.
    • Three years ago, The Gibson began an experiment that would become a community that would engage in projects to save our privacy and change the worlds of at least the members of that community.  Now this panel hopes to help you spread that change further.  In order to save hacking culture and the Internet, we must build new social networks and services that are federated and decentralized, and self-maintain our data rights.
    • Your data is not theirs to own.
    • Decentralized and federated networks are the past from which the public Internet sprung forth.  These models have started to become viable again as the social media silos have begun to be seen as dangerous to the daily operation of society, and cloud hosting has become inexpensive.  These new communities live somewhere between the BBS age and Web 2.0 - modern, nimble, creative, and largely free of undue outside influence due to advanced moderation capabilities and a hard to exploit distributed data model.
    • The presentation will tell the story of how this team did it - and how you can do it too.

  101. (2020)  Secure or Get Compromised: Unveiling the Web Security in IoT Devices  - Dr. Aditya K. Sood
    • Threats in IOT space are increasing on an exponential scale.  One of the most stringent issues encountered in IoT devices is the management and deployment of embedded web servers and security controls associated with them.  A number of security flaws exist due to the inability of imposing strong authentication and authorization controls at the granular level.  In addition, bad design practices result in giving birth to inherent vulnerabilities.  This talk highlights the state of security in embedded web servers by presenting undisclosed vulnerabilities in IOT devices.  Additionally, the talk unveils how the embedded web servers used in IOT devices are exploited by adversaries to trigger advanced cyber attacks.  There will be demonstrations and very detailed case studies will be discussed.

  102. (2020)  Securing a Remote Workforce in the Face of COVID-19 and Planning for the Future  - Christopher M. Flatley
    • As the world quickly adapted to the move to a remote workforce, it became clear which companies had prepared proper DR plans, and which were making quick decisions.  We have seen many examples where these quick decisions sacrificed security for functionality.  Christopher will discuss the obstacles that companies have faced, the ways they can be overcome, and the lingering threats that exist.  Visual and practical representations will be included, using data from almost 4000 endpoints in three countries to show what can happen when security is overlooked.  Special attention will be paid to RDP, which, while it was on a steady decline in use, has now seen a sharp increase (data from Shodan).

  103. (2020)  SE for Introverts: A Proposed Handbook  - Edward Miro
    • Many books about social engineering presume the reader has a minimum level of social ability.  In this talk, Edward provides his solution for enabling those of us on the more introverted side of things to make the skills taught in popular SE education more relevant and actionable.  He will introduce the framework, the texts, and methodology he has developed to not only teach basic social skills, social engineering, and maybe most importantly to provide a launching pad for our potential.  The dramatic possibilities that better socialization, leadership, and SE skills have towards personal empowerment is revolutionary.

  104. (2020)  Sex, Big Data, and User Autonomy  - Keegan Rankin
    • This talk will describe four mechanisms by which the big data paradigm degrades user autonomy:
      1. Sensitive data is being aggregated without transparency and without meaningful consent from users.
      2. Search functions and algorithms, content recommendations, and ads expose users to unwanted and potentially harmful content.
      3. Behavioral analytics creates profit, often by exploiting addictive tendencies, both by platform design as well as by targeted content.
      4. Dataism, a growing trust in the "objectivity" of data, justifies and reinforces norms while further marginalizing deviant identities and behaviors.
    • Each of these mechanisms are increasingly problematic when the platform in question is sexual in nature or is dealing with the collection, sharing, and use of intimate data.  Keegan will provide examples of the ways in which different sex technologies, through these mechanisms, are violating users' capacities for self-determination, sexual or not.  The technologies discussed to exemplify these mechanisms include pornography, dating apps, sex-tracking apps, and period-tracking apps.
    • The aim here is not so much to prescribe any certain path forward to overcome these complex issues, but rather to provide insight on the rapidly evolving terrain of our consumer culture, and perhaps inspire deeper and broader consideration of the relevance of technological discourse and digital privacy to sex education.

  105. (2020)  Sex Work as Artistic Practice: A Discussion on Creativity, Digital Freedom and Mutual Aid in the Age of COVID  - Lena Chen
    • Through the lens of an artistic practice that combines sex work and performance, Lena will discuss the impact of the COVID-19 pandemic on sex worker communities, best practices for mutual aid organizing, and threats to digital freedom which concern sex workers, activists, and the public at large.
    • Major crises such as COVID-19 reveal the cracks in neoliberal capitalism and who gets left behind.  Without relying on big donors or institutions, informal mutual aid networks fill the structural gaps in support for marginalized communities such as black and indigenous people, queer/trans folks, those with disabilities, etc.  Such communities have long relied on social bonds as a matter of survival while existing in a constant state of crisis and scarcity.  Sex workers, in particular, have faced loss of income as social distancing measures shut down their places of employment.  In order to provide for basic needs such as food and shelter, sex workers have spearheaded grassroots relief efforts to collect and distribute financial support to sex workers in need.
    • Since the pandemic, a growing number of people have also turned to online sex work.  Yet anti-trafficking legislation and technologies, such as FOSTA-SESTA and facial recognition software, conflate sex work with sex trafficking, rely on law enforcement and criminalization, and leave sex workers vulnerable to abuse.
    • Introduced on March 5, 2020, the EARN IT Act would amend Section 230 of the Communications Decency Act of 1996 and threaten end-to-end encryption by requiring all communication services to allow "back door" government access.  Similar to FOSTA-SESTA, which was pushed forward under the guise of ending sex trafficking, EARN IT would have massive censorship and chilling effects - and potentially threaten not only the rights of sex workers, but activists, journalists, and the general public.

  106. (2020)  Signalbots: Secrets Distribution and Social Graph Protection for Activists  - Sarah Aoun, Josh King
    • Signal is currently one of the most useful and widely-adopted tools that we have for secure communication amongst activists, journalists, and human rights defenders.  The New York Times recently reported that in the first week of June 2020, on the onset of protests and marches that swept through the United States and several other cities worldwide, Signal had 183,000 new downloads.  With the rare combination of both a hardened, widely lauded security model and a user base of millions, the Signal platform has the potential of being leveraged for a variety of different functions, with the end goal of providing additional tools for vulnerable people without requiring them to install another app.
    • To that end, the Open Technology Fund (OTF), an organization that incubates privacy and security tools (and even in the early days, Signal itself) supported the creation of Ionosphere, a toolkit for building chatbots and other tools on top of the Signal network using straightforward JavaScript libraries with example code and clearly defined APIs.
    • In this session, Josh King, developer of Ionosphere, will demonstrate how these tools have been used to create chatbots for protecting activists' social graphs, providing IRC-like services to Signal groups, and more.  Sarah Aoun, chief technologist at OTF, will discuss how OTF is using Ionosphere to extend services and tools to activists, human rights defenders, and journalists around the world.  One example of it is through the creation of a Signal VPN bot, used to distribute VPN access and other resources to people in environments with restricted Internet freedom.  Participants will come away with an understanding of the tools that exist for utilizing Signal in novel ways, how to think through the threat model and risk assessment for targeted groups, and how those tools can be expanded upon and applied to their own communities.

  107. (2020)  Solarpunk, Cyberpunk and Popculture: Technological Narratives TL;DR  - Pawel "alxd" Ngei
    • The western culture offers a very distilled narrative on what technology is and who builds, owns, and profits from it.  Most non-technical audiences are unaware of how subjective this perspective is - and how strongly it favors well-marketed multinational corporations over local solutions.  This talk will explore most problematic themes in popular culture and how they relate to the hacker approach.  The more the technology advances and becomes interconnected and complex, the less the non-technical public understands the changes, their repercussions and the policies that come along with them.  Most people end up relying on stories present in the popular culture to understand the tech world around them: the well-polished product ads hidden in their favorite films, the lone genius-inventor legends, cyberpunk visions of a world with no privacy, but so much convenience!
    • With the constant changes around, it's hard not to be future shocked and give up on any attempts of understanding the technology yourself.  The alternative narratives, especially within the hacker scene, are anything but accessible.  They're shrouded with technical terms, full of cryptic references and lacking any clear introduction.  Very few stories explain why values such as net neutrality are important without speaking code.  People need stories with clear explanations appealing to their emotions and remaining in their memories much longer than a dry technical evaluation of pros and cons.

  108. (2020)  Source Code to the Human Mind - The Science Behind Social Engineering  - Christian McLaughlin
    • Social engineering is one of the hottest talked about topics at conferences around the world.  What makes social engineering so popular and why is it so successful?  Why is social engineering so dangerous?  In this talk, Christian goes beyond discussing popular techniques and exploits that are used in the hacker community.  He will dive deep into reverse engineering the human mind and understanding how our DNA is coded to allow us to be so vulnerable.  This talk is for anyone looking to hone in on their social engineering game, as well as those who want to improve their training programs and tactics to fight this threat.
    • Regardless of what side you're on, you will enter this talk as a social engineering script kiddie and leave as a master of manipulation.  There is no going back; you will not see the world the same way again.

  109. (2020)  Stop Botting My Baby: How to Protect Your New Streaming Platform from Malicious Automation  - Randy Gingeleski
    • The launch of HBO Max yielded a lot of attention, though some of it was unwelcome.  Credential stuffers, content scrapers, and trolls lined up to test this infant streaming platform.  You'll hear how such threats were mitigated - sparing the app from media turmoil - plus maybe how to write your own (better!) bots.

  110. (2020)  The Battle for Our Emotions... Control the Narrative, Control the People  - Oryx/Sarah Kraynick
    • Information has a profound effect on the population of a society.  Controlling the information the populace sees can have a huge impact.  We saw this in 2016, and continue to struggle with mis/disinformation.
    • Society has gone down a path that is ever becoming more bleak.  Governments and society as a whole must start to own its message and have a unified front to battle the onslaught of mis/disinformation campaigns and false/fake news.  Propaganda, whether positive or negative, generally doesn't have the best connotation, and using it to affect even positive changes is not without controversy.  Putting controversy aside, if we are going to bring back some cohesion and semblance of peace, society must own the narrative - we must make sure people get accurate information and believe in the information available to them.  This talk will cover the history, tactics, and responsible use of information and behavioral mechanisms to affect positive and lasting change.

  111. (2020)  The Election System - Can We Fix It?  Yes, We Can!  - BiaSciLab
    • As security experts around the world have proven, our voting equipment and infrastructure are very vulnerable to multiple types of attacks.  Instead of focusing on problems and broken things, this talk will focus on simple fixes that vendors and governments can put into action right now.
    • Starting with the machines themselves, then moving through parts of the entire system, BiaSciLab will offer suggestions on how simple practices and changes in thinking and hiring can improve the security of the entire system.  At the DEFCON 26 r00tz asylium, BiaSciLab was one of the first to hack the mock election reporting system set up by the voting village.  Some have pointed out that this was a purposely flawed system designed for the kids to break.  However, as outlined in the Mueller report, Russian hackers used the same SQL injection technique to break into an election reporting system.  If our systems are so secure, how was this able to happen?  Lack of secure coding practices and both peer and outside review.  If proper coding review and application testing had happened, this SQL injection vulnerability would have been found and fixed.
    • Breaking down these flaws and offering real solutions for each one, BiaSciLab will bring hope in the face of this daunting and complex security problem.

  112. (2020)  The Hackbase Revolution  - Liam Kurmos
    • This talk looks at the hackbase movement and its potential to change the world by building a new economy through hacking and co-living.  Hackbases are residential hackerspaces, of which there are currently only a few in Europe.  Liam will look at the challenges faced by hackbases from the experience of the Astralship hackbase in Wales, and will consider the possibility of building local transition economies through a network of decentralised communities for co-living, co-learning, and co-creating real value.

  113. (2020)  The Pocket Organ: An Open-Source Musical Instrument  - Thomas Tempe
    • If you were to name three instruments, chances are they would all be over 300 years old.  If not, then their user interface would be inherited from centuries past.  They need to make beautiful sound while bearing archaic manufacturability constraints.  They might be terribly difficult to learn, and probably for the wrong reasons.
    • The pocket organ is about designing an instrument that fits in your pocket, plays with earphones, is extremely easy to learn, and has a depth to it, plus a set of strengths and limitations that are quite unique and useful.
    • While there are exquisite modern instruments out there, they're all legal monopolies of their respective owners, and their price typically puts them out of the reach of beginners.  The pocket organ is an attempt to change that.

  114. (2020)  The Privacy of 100+ Million Children, Families, and Young Adults is Unprotected  - Dr. Travis Paakki
    • School districts throughout the United States suffer from notoriously poor information security.  This is at a time when school district spending on technology is at an all-time high.  Why is this?  The public assumption that K-12 information security has kept pace with the rest of society is wrong.  This talk will review doctoral research that found that understaffed and underfunded districts are either ignorant of the risks or simply choose to accept them, and there is no penalty for either.  School leaders should be bound by the same expectations to secure their assets as leaders in other government agencies, and their leaders should be responsible for ensuring that students enter the world with a clean slate.

  115. (2020)  The SecureDrop Journalist Workstation: Handling Anonymous Submissions With Qubes OS  - Mickael E.
    • The SecureDrop whistleblowing platform has become the de facto standard among news organizations for communicating with anonymous sources and accepting highly sensitive leaks, and is used by over 70 media organizations worldwide.  The system was co-created by the late Aaron Swartz and first announced at HOPE six years ago.  Each SecureDrop instance is physically hosted inside a news organization, and sources communicate with journalists by accessing a web application available using Tor Onion Services.
    • In this talk, Mickael will discuss security and user experience challenges faced by journalists in opening anonymous submissions, and present the various design considerations for the SecureDrop Workstation.  Currently in limited pilot with a small number of newsrooms, the SecureDrop Workstation relies on Qubes OS and Xen virtualization to separate the various components of a journalist's workflow, which until now required the use of air gapped hardware.  Not only does it make working with source materials safer by mitigating most malware, it is also significantly faster and easier for journalists to use, and provides opportunities to integrate with other secure communication tools.

  116. (2020)  The U.S. Maker Response to COVID-19  - Johnny Xmas
    • The U.S. government has become world famous for actively ignoring the inbound China COVID-19 pandemic, opting to disband the NSC pandemic team which had been directly and recently trained to respond to these issues, splintering them into other roles.  The new Directorate for Global Health Security and Biodefense did not move to effectively prepare the country for a massive biological crisis, leaving most health care (and really, all other) facilities vastly under-prepared to handle the inbound sickness while keeping essential workers protected.  Realizing it was time to promote dev to prod, "rapid-prototypers" from all sorts of maker realms from 3D printing to sewing stepped up to donate their time, materials, machinery, project management knowledge, and even personal health in order to get these essential workers the Personal Protective Equipment (PPE) they need to ensure they can treat infected individuals while minimizing personal risk.  This presentation will provide an overview of these efforts.

  117. (2020)  The Wonderful World of Cocktail Robotics  - Johannes Grenzfurthner
    • Johannes has been co-organizing the world's leading cocktail-robotics festival, Roboexotica, for two decades.  In it, he's seen a lot of inebriating and ingeniously designed machinery.  This annual event brings scientists, researchers, computer experts, and artists from all over the world to Austria.  They build and present cocktail robots.  They also discuss technological innovations and pitfalls, futurology, and the marvels of hands-on science fiction.  It's time to dedicate an entire HOPE presentation to the concept and underlying philosophy of this bizarre and boozy endeavor.  Roboexotica is all about the flair, the atmosphere, and the personality a robot can have.  The contraptions presented can be efficient, but the primary goal is to display unique mechanical charm and character.  With thousands of guests each year, there is also an exciting educational opportunity.

  118. (2020)  Trust, but Verify: Maintaining Democracy In Spite of Информационные контрмеры (Information Countermeasures)  - Allie Mellen
    • There are many important elections this year.  As you read this, Russia is already disrupting them.
    • When we talk about election security, most people think of hacking voting machines.  But what about other cyber methods and means of disrupting an election?  What can nation state threat actors do today, tomorrow, the day of the election, and after to sow chaos and erode our faith in democracy?
    • In this session, Allie will discuss how Russia has influenced worldwide elections using cyberwarfare and the means of fighting back.  We'll understand the natural asymmetry between how Russia and other countries are able to respond, and how defensive approaches have changed since 2016.
    • Expect some brainstorming on all of the ways to disrupt an election that countries aren't prepared for.  Get ready to put your nation state threat actor hat on and disrupt some elections - and maybe even earn some ириски-тянучки (toffee-candies).

  119. (2020)  Twenty Years of Scary Technology: City Tech's "Gravesend Inn"  - John Huntington
    • City Tech's entertainment technology department has been presenting the "Gravesend Inn," a haunted hotel, for more than 20 years with annual attendance now typically around 6000.  The system has evolved from the early days of manually operated systems and a few discrete control elements to a completely networked, modern, themed attraction featuring show systems while also leveraging surveillance technologies.  This presentation will detail the history of the attraction and its technology, and offer a virtual behind the scenes technology tour.

  120. (2020)  Updates on I-star Organizations From the Bullshit Police  - Amelia Andersdotter, Mehwish Ansari, Daniel Kahn Gillmor, Mallory Knodel, Juliana Guerra
    • A panel of experts, technologists, and lawyers will give an update on several I-star organizations, namely ICANN, IETF, IEEE, and ITU.  Short presentations will touch on the major controversies in each space as they relate to human rights, namely freedom of expression and the right to privacy.  Questions to the panel from the moderator will draw out the tensions and synergies of human rights considerations in Internet governance and standards setting across the I-star bodies.  Questions from the audience are encouraged.

  121. (2020)  Weaknesses in Security Testing  - Brice Williams
    • Automation in security testing is critical to secure the rapidly growing amount of software being developed.  As much as you might be led to believe that security tools have this covered, there are clearly areas that current solutions have challenges with.  SAST, DAST, IAST, RASP, etc. tools all have their place, but we consistently see systems that use all of these and still have exploitable vulnerabilities.  In fact, there is evidence to show that more than half of all software vulnerability types cannot be discovered using security tooling alone.  As software development techniques evolve, security tools often have trouble keeping up.
    • This talk will include a number of specific vulnerability types that security tools often struggle to find, and how you can exploit these gaps.  For example, tools are notorious for missing Insecure Direct Object Reference (IDOR) weaknesses.  The information presented is a result of commercial product penetration test engagements involving many different types of systems over the last decade.  These white-box style assessments include security architecture review, environment infrastructure inspection, and manual analysis of millions of lines of source code.
    • Also discussed will be complementary protections like developer training, security unit testing, third-party penetration testing, and bug bounty programs to help give you a more complete picture of how to address weaknesses that we commonly see slip through the automation cracks.

  122. (2020)  Weeding Data Space  - Joel Austin, Kwan Q Li
    • As an ongoing investigation which unpacks the dehumanization conspiracy of growing data domination, this spatial research will leverage on the turmoiled case of Hong Kong, as a highly idiosyncratic context, to illustrate how the unheeded culmination of data centers has been silently engulfing urban space.  Stemmed from an extensive thesis of typological analysis and speculative writing, the talk attempts to hypothesize on antagonistic potentials through the lens of performative theories, edge computing, and more.  Especially in the age of pandemic in which our lifestyles are increasingly digitized, discussion on our incessant migration to the virtual realm and the emergence of city relics is unprecedented and timely.  The presenters hope to raise awareness of this transformation of urbanism rapidly driven by burgeoning data consumption, and to invite imagination on alternative futures.

  123. (2020)  We Need to Talk About Amazon: An Introduction to Capitalism  - Johannes Grenzfurthner, Jasmin HagendorferJohannes Grenzfurthner, Jasmin Hagendorfer
    • Amazon is an American multinational technology company based in Seattle.  It focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence.  Amazon is called "one of the most influential economic and cultural forces in the world" and the world's most valuable brand.  For nerds who grew up in the 1980s, it's like a cyberpunk dystopia's wet dream come true.  Amazon has moved into health care and insurance.  It has dug deeper into AI and automation, and bolstered its in-home delivery services.  But that's not enough to understand the brutal capitalist force it represents and the future Jeff Bezos wants to create.  This discussion will look at some of the curious aspects of this company, along with what we can learn from its behavior about late (((capitalism))).

  124. (2020)  When Cops Get Hacked: Lessons (Un)Learned from a Decade of Law Enforcement Breaches  - Madison Vialpando, Emma Best, Dave Maass
    • More than 125 U.S. law enforcement agencies have suffered some form of hack or data breach over the last ten years.  Journalism school graduate Madison Vialpando has been working with the Electronic Frontier Foundation to build a dataset compiling all the ransomware, DDoS attacks, physical data theft, and servers and surveillance technologies exposed online.  In this talk, she will explain how the dataset works, the trends revealed by the data, some of the most interesting case studies, and whether law enforcement is actually learning anything from these incidents.  Dave Maass will talk about the Electronic Frontier Foundation's security research into automated license plate readers and other unsecured surveillance tech, while transparency activist Emma Best of Distributed Denial of Secrets will provide an overview of BlueLeaks - one of the largest dumps of internal police documents in history.

  125. (2020)  Who Has Your Face?  The Fight Against U.S. Government Agencies' Use of Face Recognition  - Jason Kelley, Dr. Matthew Guariglia
    • The fight against government use of face recognition technology is an important one, and one that civil liberties and other groups have come at from many different angles.  Unfortunately, the technology is already out there - in use - and endangering people's privacy.  Due to differing laws, regulations, and data-sharing agreements between federal, state, and local agencies across the country, U.S. residents and visitors frequently have their image not only collected and stored for facial recognition purposes by the government, but often also secretively shared between dozens of agencies.  Because of the complexity of these laws and agreements, it's very difficult to learn who exactly has your image.  It can take a hacker mindset to learn where your image is - FOIAs, online research, even contacting individuals directly at government agencies.  Using all of these methods, EFF developed a new interactive website to explain to users which agencies might be using their image for face recognition - and to spur them to act.  The speakers will explain issues with facial recognition technology; what sort of advocacy has been effective in the past; where we stand on federal, state, and local regulations; and discuss how they did the research, design, and creation of the whohasyourface.org website and its result on laws and advocacy, as well as suggest ways that others can build on this research.

  126. (2020)  Zbay, Fighting FAANG, and the Quest for a Peer-To-Peer Messaging App That "Just Works"  - Holmes Wilson
    • We live in a time of tech monopolies, again.  We escaped Microsoft's 1990s desktop monopoly to hurtle into the FAANG monopolies, by walking a path where browsers, OSes, and developer tools might be free software, but the platforms we used to connect and collaborate were more locked down than ever.  But what if free software was not just a window to a locked down world?  What if the world "out there" where we speak and collaborate emerged exclusively from free software running on our laptops and phones, connecting in a peer-to-peer network?  The P2P "stack" is growing fast in maturity and capability; how far can we take it?  Messaging apps seem to be the most popular user-facing software; can we make one of those?  This talk will survey approaches to P2P messaging apps and discuss tradeoffs in the context of a specific app: Zbay, which is being built based on Zcash and Tor, and which just launched in beta.



A New HOPE





  1. (2022)  A New HOPE Open Ceremony  - Greg Newby, Jason Scott, Mitch Altman, Evil Corley
    • At last, it's the culmination of years of preparation in finding a new home and getting past this damn pandemic.  As A New HOPE finally begins, we're happy to also help kick off our sister conference May Contain Hackers (MCH), taking place simultaneously on a campground in the Netherlands.  There will be plenty of communication between the two throughout the conference.
    • Note:  We lost audio for a few minutes in the middle of this presentation.  Please let us know if you have an audio transcript or are able to read lips and tell us what we were saying.
    • AI Transcript

  2. (2022)  Secrets of Social Media PsyOps  - BiaSciLab  
    • Psychological warfare thorough social media is one of the most powerful weapons in today's political battlefield.  PsyOps groups have figured out how to sharpen the blade through algorithms and targeted advertising.  Nation states are using PsyOps to influence the citizens of their enemies, fighting battles from behind the keyboard.
    • In this talk, BiaSciLab with cover a brief history of PsyOps and how it has been used both on the battlefield and the political stage - followed by a dive deep into how it works on the mind and how PsyOps groups are using social media to influence the political climate and elections worldwide.
    • AI Transcript

  3. (2022)  ActivityPub Four Years Later: The Good, the Bad, and the Fedi  - rolltime  
    • ActivityPub celebrated its fourth anniversary as a W3C standard this January.  The spec defines protocols which allow anyone to run their own social media server, which can then talk to everyone else's servers, a technique known as "federated networking."  When ActivityPub was first released, many believed it would change social media forever, bringing about the end of monolithic surveillance networks and ushering in an era of democratized local communities.  Four years later, while the Fediverse plays host to a thriving community and unique culture, it remains a nonentity by the standards of social media giants.  Why is this?  How has ActivityPub created a constructive and enjoyable social media experience while also failing to bring that experience to a large audience?  And what can this tell us about the possibilities and limitations of anarchistic spaces as a whole?
    • AI Transcript

  4. (2022)  Why Building Digital Libraries Matters  - Davide Semenzin  
    • This talk will examine digitizing books at scale and some interesting technology tidbits as to how an operation like this actually works.  For example: why is the page-turning not automated?  What are the building blocks of such a system?  What were some of the most significant (and unexpected) issues along the way of scaling this system to digitize over one million books a year on the Internet Archive books digitization platform?
    • Why do this in the first place, one may ask?  In short, because accessibility drives preservation and, for an increasing amount of use cases, if a book is not easily accessible online, it might as well not exist.  Moreover, digital artifacts have specular properties to the physical ones in that they are easy to distribute (and easy to censor!), which means that once the expensive task of creating one is done, the problem is only one of access control.  There is a lively policy discussion about what these access controls can and should be, but the argument here is that not only is it important that we invest in creating the digital artifacts, but also that these are maintained by some type of lender of last resort.
    • This talk will discuss how people can make digital libraries part of their lives, and how these libraries can improve those lives.  There is often a misunderstanding of digital books being an alternative to physical ones.  In fact, they are a complement, working together to give us better knowledge.  Digital books allow us to do things like full text search, direct linking, and can support digital media embedding.  This talk will also include a discussion on a few of these use cases, as well as examples of tools that are available to enrich one's reading and learning experience.
    • AI Transcript

  5. (2022)  Six Years Later & Worse Than Ever - The Espionage Act, Computer Fraud & Abuse Act  - Jesselyn Radack, Carey Shenkman  
    • The Trump administration continued the trend of using two antiquated laws - the Espionage Act of 1917 and the Computer Fraud and Abuse Act of 1986 - as tools to restrict the public's right to know.  Trump's Justice Department sent numerous truth-tellers to prison, and in 2019 charged Julian Assange, who is neither a government employee nor a U.S. citizen, under both laws.  The current legal landscape has unprecedented implications for national security journalism, transparency, and the use of anonymity and source protection tools.  Join two human rights attorneys who have worked closely on issues surrounding these laws for a conversation on what's at stake for activists, journalists, and researchers; the recent traction in Congress for reforming both laws; and the necessity for doing so.
    • AI Transcript

  6. (2022)  Porn Platforms Hate Them for Exposing Their Mischief With These Two Weird Tricks  - Giulia Corona, Alessandro Polidoro  
    • The non-profit organization Tracking Exposed (tracking.exposed), which fosters digital rights and algorithm accountability, has developed a set of free-software tools (Potrex and Guardoni) with the intent of bringing light into the underlying mechanisms of one of the major porn platforms existing nowadays.  Thanks to these tools, Giulia and Alessandro have achieved an unprecedented angle of view over biases and data processing malpractices that may affect these websites, collecting precious evidence that has proven useful for carrying out academic research and even digital forensics investigations.  Their goal is to give empowerment to the users and help them reclaim their rights recognized by the European General Data Protection Regulation (GDPR) and even more.  During this talk, they will present the research they have conducted regarding the abuses spotted on a porn platform whose algorithms seem to be operating in a seriously biased way.  They will then explore signs of possible data protection law violations and will imagine together strategies and methodologies for the upcoming analysis of these platforms.
    • AI Transcript

  7. (2022)  All About RADIO WONDERLAND  - Joshua Fried  
    • RADIO WONDERLAND will be performing live at A New HOPE.  This talk will expose the how and why.  As to what, RADIO WONDERLAND pulverizes mass media into little bits that dance; live commercial radio becomes recombinant funk, controlled by old shoes Joshua hits with sticks (he's a drummer) and a vintage Buick steering wheel (he's also a... wheel player).  All the processing is live, though his custom Max code.  This talk will look at some of that code - which is nicely graphical - and will discuss the place of high-level programming environments such as Cycling 74's Max which often comes with their own low-level escape hatches.  But that's just coding - nothing particularly "hackery" about it.  It's what RADIO WONDERLAND does with mass media, live performance, and ordinary objects that seems to tickle hackers and the HOPE community.  That will also be discussed here.
    • AI Transcript

  8. (2022)  Moving Beyond Amazon Self-Publishing Purgatory  - John Huntington  
    • Back in 2014 at HOPE X, John did a talk called "A Self-Publishing Success Story" detailing his process moving a book from a publisher to self-publishing on Createspace/Amazon.  He had a good run on Amazon, updating the book again in 2017.  Then, in 2018, Amazon merged Createspace into its "Kindle Desktop Publishing" (KDP) platform.  In 2020, John decided to update several paragraphs in the 475-page book, and this attempt at a simple text change led to his book being stranded in a virtual, dystopian Amazon purgatory.  The only reasonable way out was to abandon Amazon KDP altogether.  This led to moving everything over to IngramSpark for print copies, Google Play Books for ebooks, and DPD for individually watermarked, DRM-free PDFs.
    • In this talk, John will discuss the horrors of his Amazon nightmare, successfully moving onward, the self-publishing process in 2022, and the economic aspects of his recent self-publishing experiences.
    • Blog Post
    • AI Transcript

  9. (2022)  The CFAA Has Come a Long Way, or Has It?  - Alexander Urbelis, Joel DeCapua, Jay Kramer  
    • On May 19th, for the first time in nearly a decade, the U.S. Department of Justice revised its guidelines for bringing charges under the Computer Fraud and Abuse Act (CFAA), instructing federal prosecutors to decline prosecutions if the conduct at issue involved "good faith security research."  Under these new guidelines, accessing a computer "for purposes of good-faith testing, investigation, and/or correction of a security flaw or vulnerability," if carried out in a way designed to avoid harm to individuals and the public, would not be a criminal offense.
    • On the books since 1986 - and enacted into law in direct response to the classic hacker flick WarGames - the U.S. Supreme Court and various lower courts have been continually shrinking the once-broad scope of the CFAA, and now DOJ itself has reconsidered the wisdom of its past practices.
    • This talk will explore the contours of this new policy and how it affects the hacker community, including topics such as:
      • Is this change too little too late, especially since it was an expansive use of prosecutorial discretion that lead to CFAA charges against Aaron Swartz in 2011 that tragically lead to him taking his own life in 2013?
      • What was the driving force behind this radical policy shift?
      • What binding effects do these guidelines have on U.S. Attorneys' Offices?
      • What counts as "good faith security research?"
      • What does not count as "good faith security research?"
    • AI Transcript

  10. (2022)  Nikola Tesla's Predictions Today  - Ed Wilson, Jeffrey Velez, Douglas Borge, Dr. Bryan J. Field  
    • Explore the predictions of science visionary Nikola Tesla and where they stand today in this interactive discussion with staff of the Tesla Science Center at Wardenclyffe.  This presentation will delve into Tesla's prescient ideas and futuristic inventions, some of which were so far ahead of the time in which he lived that they were often dismissed and only today are realizing their potential.  The talk will include an update on Wardenclyffe, Tesla's only surviving laboratory, with an exclusive look at what the future holds.
    • AI Transcript

  11. (2022)  Hacking Local Politics: How We Banned Facial Recognition in Minneapolis  - Munira Mohamed, Chris Weiland  
    • The lines between technology and society are becoming blurred to the point of nonexistence.  The software we build oftentimes has more impact on the day to day lives of ordinary people than the laws passed by local governments.  For reasons both practical and moral, it is becoming increasingly important for those of us with technical expertise to become more involved with the political process.
    • But if we want to move beyond armchair activism, we need to understand the system we are trying to hack.  Drawing on the panelists' recent experiences with passing an ordinance banning the government's use of facial recognition in Minneapolis, and their work creating the Safety Not Surveillance Coalition, this presentation will offer concrete steps on how you can transfer technical expertise into effective political change.
    • AI Transcript

  12. (2022)  How to Run a Top-10 Website, Publicly and Transparently  - Kunal Mehta  
    • Wikipedia is the only top-10 website that is operated by a non-profit, but more importantly, runs fully transparently.  Literally anyone can view detailed monitoring graphs for individual services and servers, see alerts fire in real time, and watch as engineers deploy code and debug problems live.  It's not a one-way street.  Participation from volunteers is encouraged and welcomed, with the Wikimedia Foundation giving out sever access to trusted volunteers, allowing them to view private logs and deploy changes.  Even amongst smaller or other non-profit/public interest websites, this level of transparency and openness is really unheard of.  Yet it is key in what has made Wikipedia such a force for good and, really, the Internet a better place.  This talk will discuss the advantages and disadvantages of running a website in this way, including looking at case studies where this level of transparency enabled volunteers to provide key insights that fixed bugs and outages, saving the day.
    • AI Transcript

  13. (2022)  A New HOPE Keynote and Q&A with Sophie Zhang  - Sophie Zhang, Yan Zhu  
    • Facebook whistleblower Sophie Zhang will share insights, in discussion with Yan Zhu.  Sophie became a whistleblower after spending two years and eight months at Facebook, personally catching two national governments using the service to manipulate their citizens, and also revealing some troubling decisions made by Facebook.
    • In addition to this discussion with Sophie, Yan also ran the Q&A with Chelsea Manning at The Circle of HOPE in 2018.
    • AI Transcript

  14. (2022)  Leaks and Hacks: Four Years of DDoSecrets  - Lorax Horne, Freddy Martinez, Emma Best  
    • Distributed Denial-of-Secrets has published more than 70 terabytes of data since launching in 2018.  The transparency collective formed to capture the data released by hackers and leakers, and to keep documents of historical importance available to journalists and other researchers.
    • DDoSecrets has since become a stable repository for many sorts of archives, despite pushback and censorship.  During Russia's war on Ukraine, hacktivists took a special interest in Putin's sprawling bureaucracy, exfiltrating reams of records from the erstwhile insular country.  With their mission and experience publishing data like BlueLeaks, DDoSecrets was well-placed to archive the informational spoils of the cyberwar.
    • They believe that data can only be a part of the story, so they rely on the public to examine their datasets in detail.  They have made mistakes along the way.  The project is a work in progress.  They want their existence to provide inspiration for future leaks publishers, and hope for sources.  Come to hear them discuss the strategies that they've seen work.
    • AI Transcript

  15. (2022)  Mad as Hell: Is There an End to Subversion?  - Johannes Grenzfurthner
    • We (almost) made it through a pandemic abyss, the Trumpian "fake news" wars, right-wing Q/Anon trollery, and pathos-laden political truthiness.  As a provocateur, political artist, and activist, Johannes Grenzfurthner asks the simple question: What is there still to be done?  How can there be subversion in a world that is hellbound on waging war with rationality?  Is there still a potential in radical pranks and stunts in a mediaspace that is built on spectacle?  What can really be done if you are (to quote a 1970s classic) mad as hell, and you are not going to take this anymore?
    • AI Transcript

  16. (2022)  Online Operations for Protests and Pranks: How to Get the Truth Out  - Jim Haugen, Sam Peinado  
    • As the Internet centralizes, it gets harder to keep sites up that disrupt corporate power.  In 2020, several members of climate activist group Extinction Rebellion took their street-based disruptions online, to get the attention of big companies that were contributing to climate collapse.  They adopted the tactics of prankster/activists The Yes Men.  They began with a viral pseudo-announcement from Google regarding their funding of climate-denying lobbyists.  The activists recently went after a refinery project in Wisconsin, resulting in dozens of articles and TV news stories.  These activities and other similar online protests invite takedowns galore from target corporations.  This presentation will explore learnings for keeping a site up and maximizing impact in the face of legal complaints and takedown requests targeting domain registrars, Internet service providers, email service providers, and social media networks.
    • AI Transcript

  17. (2022)  Demand Protest: Manufacturing Truth in a Post-Truth Era  - SquareMatrix  
    • Online hoaxes have evolved from the realm of folk tales and anarchic fun to becoming one of the primary weapons of choice in the post-truth world, now used by intelligence agencies, corporate interests, and even hacktivists.  This talk will examine the history of online hoaxes and propaganda while dissecting the tools and tactics that have become the modern weapons of political warfare.  SquareMatrix will provide a behind-the-scenes anatomical look into the inner workings of Demand Protest, an online political hoax purporting to be a company running large-scale paid protesting and public influence operations.  This project briefly captured conservative media's imagination in the run-up to the 2016 election and ultimately forced them to debunk a false narrative about paid protesters that they themselves had created.  The tactics and learnings from a hoax that caught the attention of The Washington Examiner, InfoWars, The Drudge Report, and Tucker Carlson will all be laid bare by those that perpetuated it.  Why leave shaping reality to the bad guys?
    • AI Transcript

  18. (2022)  Hackers Got Talent  - Jason Scott and Friends  
    • Do you have a cool talent or hack?  Here's your chance to present it onstage to a large audience of enthusiastic hackers, hosted once again by hacker archivist Jason Scott.  Onstage hacks will be judged by a combination of panelists and audience.  First place wins a valuable prize!
    • AI Transcript

  19. (2022)  ARTificial Intelligence - How IP Law Handles Machine Creations  - Ed Ryan  
    • The development of sophisticated machine learning models in recent years has been pushing into realms of human creativity, and that has implications for patent and copyright law.  Can a machine be an "inventor?"  Does the machine's output qualify for copyright protection?  The development of the DALL-E and DALL-E 2 systems directly call the very concept of "creativity" into question, while the former is being actively litigated in courts around the world.
    • AI Transcript

  20. (2022)  Using Security Automation to Organize Your Cyber Threat Intelligence Knowledge  - Andrew Ku  
    • Enterprise security tooling is expensive.  Enterprise intelligence tooling is expensive.  Enterprise cyber threat intelligence tooling doesn't have to be.  OpenCTI is an open-source comprehensive platform that allows organizations to manage, structure, store, organize, and visualize their cyber threat intelligence knowledge and observables.  It uses a modern tech stack built on NodeJS, Python, GraphQL, Elasticsearch, RabbitMQ, and Redis.  It boasts a bustling community that provides active support to newcomers and encourages contributions from the experienced.  It currently possesses the ability to import, enrich, and funnel data to/from 50+ common household names in security products!
    • This talk will outline how the platform can be deployed, scaled for high availability using cloud native strategies, and utilized by strategic and technical cyber threat analysts at any seniority level.  The talk will also touch upon how security automation fits in the grand scheme of things to compound the operational work by other security teams.
    • AI Transcript

  21. (2022)  Electronic Warfare on a Budget of $15 or Less  - Lucas Rooyakkers  
    • You are constantly being irradiated by a plethora of gadgets and gizmos firing photons through your body every second, so why not figure out how to read those airwaves?  Learn to, on a $15 budget: plot the flight paths of dictators; stingray your own phone; track the movements of fishing fleets; listen to the local taxi dispatch; find signal from outer space and other radio astronomy; read airline pilots' text messages; get pinged when pager messages are sent; hack Wi-Fi (but with an SDR); communicate via shooting star (really); and much, much more!
    • Radio Scanner Modifications and Information
    • GBPPR Special Collection Service
    • AI Transcript

  22. (2022)  How to Bargain With a Black Box: Hacking a Path to Data-Driven Organizing  - Dan Calacci  
    • Workers across the world are increasingly subjected to data-driven and algorithmic management, where digital tools influence and define their working lives.  As traditional employment relationships break down, these tools are increasingly filling the gaps.  How can workers fight back?  In this talk, Dan highlights several recent projects that leverage worker-owned data for organizing campaigns, using tools developed in collaboration with workers and organizers.  Each project represents a different way that data can be used to fight for worker rights.  In the first project, he will show how even simple tools like a chat bot can be used in an organizing campaign to scale an algorithmic audit of a delivery platform company.  In a second, Dan will discuss his experience helping develop technology to measure and fight wage theft in a "data for unions" workshop with trade unions across the global south.  He will then go over the lessons learned from these projects, and outline the digital future for labor rights and collective action.
    • AI Transcript

  23. (2022)  Revolution During Disintegration: A Brief History of Yugoslav Computing  - Vlado Vince  
    • The socialist Yugoslav state was in many ways an aberration of the polarized Cold War period.  Socialist, but not Soviet-aligned; friendly, but not exactly allied with Western Europe and the U.S.; its unusual position produced unique developments in computing.  At our current tumultuous historical moment of the pandemic, worsening climate crisis, and most recently the Russian invasion of Ukraine, we may be witnessing another global polarizing moment that may have long term political, cultural, and technological consequences.  By looking at unusual technological developments from the late Yugoslav period - the curious case of Iskra Delta and DEC collaboration, the history of the Galaksija (the Yugoslav DIY microcomputer), and the development of JUPAK (Yugoslav Packet Network) - Vlado will offer a few lessons as we potentially move into a world where technology is once again an integral part of geopolitical conflict.
    • AI Transcript

  24. (2022)  Five Dollar Cyber Weapons and How to Use Them  - Kody Kinzie  
    • For five dollars, hackers can buy more power than ever before thanks to low-cost microcontrollers!  The cost of sophisticated attacks has dipped below five dollars, but knowing the capabilities of each platform can be confusing.  Kody will highlight free projects demonstrating advanced Wi-Fi phishing, HID bad USB attacks, and bleeding edge Wi-Fi research using the ESP8266, ESP32s2, and other low-cost microcontrollers!  Finally, he'll show how anyone can get started programming their own custom hacking tools using beginner CircuitPython.
    • AI Transcript

  25. (2022)  Seize the Means of Computation: How Interoperability Can Take the Internet Back  - Cory Doctorow  
    • This is a talk for people who want to destroy Big Tech.  It's not a talks for people who want to tame Big Tech.  There's no fixing Big Tech.  It's not a talk for people who want to get rid of technology itself.  Technology isn't the problem.  Stop thinking about what technology does and start thinking about who technology does it to and who it does it for.  This is a talk about the thing Big Tech fears the most: technology operated by and for the people who use it.
    • AI Transcript

  26. (2022)  Engineering Your Own Disease Eradication Program  - Michael S. Laufer  
    • How many times have you read a PopSci article claiming that a cure or a treatment of a disease has been discovered, only to never hear about it again?  Sometimes it's because the journalists were a little overzealous in their estimations.  But just as often it's merely because the treatment won't play well in the marketplace, and the cure just sits on the shelf, inaccessible.  The Four Thieves Vinegar Collective has been busy the last few years, not only unearthing specific examples of this, but also developing tools for individuals to develop their own discovery and manufacture processes.  At this talk, a number of therapeutic regimens will be released, along with the newest version of the MicroLab, and online tools for chemical synthesis pathway discovery, which will go live for the first time and be accessible to the audience in real time during the talk.  Requests will even be taken live on stage.  It's worth stopping by and seeing if there's an easy way to cure or treat the disease you think is the most important to cure.
    • AI Transcript

  27. (2022)  The Mathematical Mesh  - Phillip Hallam-Baker  
    • Another day, another data breach compromising personal data.  Why don't they just encrypt?  Encryption is easy, but being able to access your encrypted data and use it on all the devices you use and share it with your co-workers is hard.  The Mathematical Mesh is an open infrastructure that addresses the missing piece in Public-Key Infrastructure: the management of the private keys.  Devices connected to a user's personal Mesh are automatically provisioned with precisely the set of keys, credentials, and data required to perform their function.  The Mesh uses structural and threshold cryptographic techniques to achieve an unprecedented level of security without requiring the user to think about cryptography or security.  The only configuration steps required to configure a device to use the Mesh replace prior network and platform configuration steps.  And when the Mesh code is complete, these can be made as simple as a one-time QR code scan.
    • AI Transcript

  28. (2022)  In Which Interlaced Video Digitization Makes Me Forget About Dying (For a While)  - Jason Scott
    • A side-project to address a growing stack of videotape causes historian and archivist Jason Scott (textfiles.com, Internet Archive) to consider what exactly it means to try and capture data before it disappears forever; and along the way he takes you through oblivion, redemption, hopelessness, and perhaps some small amount of compassion.
    • You will also learn how to deinterlace video.
    • AI Transcript

  29. (2022)  Plausible Deniability and Cryptocurrency Privacy  - Lane Rettig, Michelle Lai, Arctic Byte  
    • Hackers around the world use cryptocurrencies like Bitcoin and Ether every day under the mistaken assumption that these networks are somehow privacy-preserving (often conflating pseudonymity for privacy).  This couldn't be further from the truth, as it is in fact often easier to trace crypto transactions than fiat transactions.  Even so-called private networks like Zcash and Monero aren't failsafe from a privacy perspective.  However, with a few tricks and tools, it is possible to preserve privacy on cryptographic networks in a robust way.  This panel will feature three privacy experts discussing best practices for obscuring one's identity and not leaving a trace while transacting on some of the most important widely-used blockchains and cryptocurrencies such as Bitcoin and Ethereum.
    • AI Transcript

  30. (2022)  Travel Hacking in a Still-Pandemic World  - TProphet  
    • The pandemic turned the world of travel upside down, introducing many new restrictions and requirements.  All of a sudden, breezing through international transit zones isn't always a simple and trouble-free experience.  The financial impact of the pandemic on the airlines has also been sharp and stark, resulting in airline bankruptcies and consolidations leading to loyalty program devaluations.  All of this has had a major impact on planning international travel, especially hacks (such as unusual routings) that were previously possible.  In much of the world, the pandemic isn't yet considered over, and the impact on international travel remains far-reaching.  However, travel hacks are still possible!  TProphet will help you understand what is practical, and what could torpedo your plans.
    • Seat 31B
    • AI Transcript

  31. (2022)  Tracking Android Malware and Auditing App Privacy for Fun and Non-Profit  - Bill Budington  
    • Our devices are a window into our souls, and contain a vast trove of information that is valuable to both data-driven big business and hackers alike.  On the surface, a popular social media app promoted on the Google Play Store and a piece of malware side-loaded onto a device may seem very different.  From the perspective of reverse engineers and analysts of Android apps, however, the tools and methodologies are the same.  Using a combination of static and dynamic analysis, we can begin to understand the behavior of apps that are installed on our devices, and see exactly what data they are siphoning and sending out.
    • In this talk, Bill will cover the tools, techniques, and device configurations used to conduct a privacy audit of a popular app or a behavioral analysis of a piece of malware.  Drawing from his investigation of the popular Ring doorbell app to his more recent work dissecting a piece of malware which used Tor to discover a command and control (C2) server, this talk will be infused with real-world research and examples of both.  In addition, the "apkeep" tool developed at EFF provides a powerful addition to the toolbox for anyone interested in downloading apps from various sources and app markets.  Finally, he'll present a configuration of a single Android device that can do real-time interception of encrypted network communication from apps run on it while on-the-go, which can be useful for when apps change based on location or user behavior.
    • If your interest is in reverse-engineering Android malware, in auditing the sensitive information which is habitually gathered by ostensibly legitimate data-driven businesses, or just in learning a little more about the world of app analysis, this talk will have something for you.
    • AI Transcript

  32. (2022)  Quantum Computing: It's Not Just Sci-Fi Anymore  - Kevin Carter  
    • This talk will focus on the current state of quantum computing, including current infosec and other scientific use cases for post-quantum cryptography, open-source and proprietary quantum development toolkits, and information about how to get involved in the quantum computing community.  Quantum cloud computing technology will be discussed in depth, and there will be demos of quantum computing systems throughout the presentation.
    • AI Transcript

  33. (2022)  VOID LOOP () - Minecraft as My Musical Instrument  - Ramon Castillo  
    • VOID LOOP () is a collection of performances in an elaborate Minecraft world.  Audio from the game is routed through Ableton Live for some live looping and other antics.  This collection of pieces takes place in the Minecraft void biome.  The title is a reference to the biome, the looping techniques Ramon uses, and the Arduino function: the Arduino IDE was used to program a Teensy 3.2 board that a Twitch audience can use to control his Minecraft character.  Chat users can enter commands like !left and !right to turn his character at times during the performance.
    • In addition to using widely available Minecraft mods and resource/data packs, VOID LOOP () harnesses the power of Ableton Live and Max for Live for both signal processing and game control.  Movement can easily be triggered by elements like MIDI messages or audio envelope following.  Furthermore, Ableton Live and Max for Live can be extended using script-oriented objects (ClyphX Pro and node.js), making for an incredibly connected environment.
    • Finally, the video signal from Minecraft can be processed in novel ways using color keying.  Specifically, VOID LOOP () turns part of the world into a "green screen."  Additional video processing happens in VDMX, a real-time video processing environment with sound reactivity and MIDI/OSC connectivity.
    • The development of these performances has led Ramon to develop numerous projects with his students at UMass Lowell (UML) that involve Minecraft as an immersive and collaborative musical instrument.  In-game logic, scripting, and hackability foster a musically conducive environment where composers and performers can collaborate on highly expressive works.  While these projects were created as part of the Contemporary Electronic Ensemble, they led to the creation of UML's Video Game Ensemble where ultimately any game could be used as an instrument.
    • AI Transcript

  34. (2022)  From Mind Control to Mind Expansion: Hacking Technology to Rebuild Our World  - Javair Ratliff, Geva Patz  
    • It's time for hackers to think bigger and act bigger.  We're used to poking at systems and finding the weak spots so they can be patched before things break catastrophically.  But what do we do when the system is broken beyond hope of patching?  When the magical power of technology that we see and understand so well is co-opted for cheap conjuring tricks for the ends of persuasion and power?  When we have a technological infrastructure that supposedly "connects" billions of us to each other, but which, because it struggles to escape the gravity well of these distorting motivations, fails to enable us to effectively support each other even in the face of a global existential threat?
    • This will be a HOPEful, interactive session where Javair and Geva will take some elements at the edge of today's technology - virtual reality, brain-computer interfaces, AI - and apply the hacker spirit to use them in ways the system never intended, to allow us all to see and act on more forward-moving visions of the future together.
    • AI Transcript

  35. (2022)  Hack the Planet... Step 1, Step 2, Step  - Tom Brennan  
    • Penetration testing has existed as a cyber security assurance activity for many years.  Although frequently used, the phrase lacks clear definition and is often misunderstood.  For many individuals, phrases such as security auditing, penetration testing, vulnerability analysis, ethical hacking, and red teaming all mean the same thing.
    • CREST has been accrediting penetration testing companies since 2006 and by the end of 2021, it had assessed more than 250 organizations that deliver penetration testing services around the globe.  During this time span, the expectations around what a penetration test is have evolved.  In parallel, the toolsets, platforms, and delivery methods that can be used to provide penetration tests have changed significantly.  Over the past 15 years, the number of organizations across the globe that procure penetration tests has increased markedly and, accordingly, it is CREST's considered opinion that there is increased need to define a set of minimum expectations that should be associated with a penetration test.
    • AI Transcript

  36. (2022)  Right to Repair - You Should Have the Right to Fix What You Own  - Louis Rossmann  
    • In this talk, Louis will share his experiences of showing manufacturers, such as Apple, that it is possible and desirable for their customers to repair their own devices.  After years of creating repair how-to videos on his YouTube channel, he decided that he wanted more people empowered to repair their devices, rather than replace them with new ones - with the old ones becoming toxic waste in landfills.  After years of seeing manufacturers fighting hard to keep people from having the right to repair their own property, Louis decided to fight back and become involved with "Right to Repair," which has, over time, become a movement, with the very real possibility of becoming law.  This talk will show you how worthwhile - and fun - it is to repair what you own!
    • AI Transcript

  37. (2022)  Breaking 19th Century Encrypted Newspaper Ads With Modern Means  - Elonka Dunin, A.J. Jacobs, Klaus Schmeh  
    • In the 19th century, encrypted newspaper advertisements were a common method of communication.  They were used to transmit everything from love messages and business information to family news.  Publication in a newspaper ensured that a message could be received anonymously and virtually everywhere, even by people on the go.  Encryption ensured that (at least in theory) only the intended recipient could read the note.  The three presenters of this talk have collected hundreds of encrypted newspaper ads from the 19th century from England, France, and the United States.  Some of these ads are unique while others form series of messages, the longest of which includes over 50 advertisements published over several years.  Some messages were solved quickly, some are still being solved today, and others remain unsolved.
    • To solve ciphertexts of this kind, modern codebreaking tools can be used, such as the open-source software CrypTool 2 or the free online service dCode.
    • This talk presents the most interesting newspaper ads from the lecturers' collection along with the background stories.  It is shown how these messages can be broken with modern algorithms implemented in free software tools.  In addition, some of the toughest unsolved advertisements are introduced and potential solution approaches are explained.
    • AI Transcript

  38. (2022)  Unpickable But Still Unlockable: Lock Bypass Tricks in the Field  - Bill Graydon, Karen Ng  
    • Physical red-teams rely heavily on nondestructive bypasses when doing vulnerability assessments: under-the-door tools, latch-based attacks, climbing through vents and around walls and fences.  But how well do these techniques actually work in the field - when time is of the essence and it's not in a controlled training environment?  This talk will focus on a plethora of real life successes, failures, and lessons learned for how to make these techniques work in practice.  Karen and Bill have talked extensively about the mechanics of lock bypass in the past - most notably at the Bypass 101 sessions Karen gives with the Physical Security (formerly Lock Bypass) Village.  They will recap the fundamentals of each technique here too - but now you'll get to learn from their years of experience in what actually works.
    • AI Transcript

  39. (2022)  Executive Order 14028 & Zero Trust Architecture - Now We Must, But What It Means?  - Harri Hursti  
    • The President's executive order on "Improving the Nation's Cybersecurity" (EO14028) issued on May 12, 2021 started a process, which was followed on January 26, 2022 by a "Federal Strategy to Move the U.S. Government Towards a Zero Trust Architecture."  This calls for wide cooperation between government, public, and private sectors.  The executive order also calls for "enhancing software supply chain security" with an emphasis for which open-source software would be the most reasonable solution.  As response to the recent war in Ukraine, major governments have asked the private sector to "shield up," increasing the urgency of adaptation on the private sector - and recent successful penetrations of critical systems overseas should be seen as a foreshadowing of things to come.
    • Zero Trust is a journey, and an over-hyped term.  What does it mean in this context?  The cornerstone these implementation requirements are built upon is the "identity management," not only for humans, but also for devices, instances, and services.  "Once in a million" used to be a moniker for acceptable risk, but with the rate velocity of business and the volumes that transactions have reached, it may translate to seconds instead of years.  And the elephant in the room: How do we manage identities without sacrificing privacy?
    • AI Transcript

  40. (2022)  How Hip-Hop Can Inspire the Next Generation of Tech Innovation  - Manny Faces  
    • Hip-hop is a world-class disruptor.  It has transformed music, popular culture, fashion, business, and advertising, creating (and upending) massive industries in its wake.  This talk explores the enormous innovative potential hip-hop music and culture continue to exert across multiple fields and disciplines including science and technology, education, health and wellness, politics and activism, journalism, fine arts and... well, everything.
    • AI Transcript

  41. (2022)  Project MKULTRA Cracked: Declassified CIA Brain Warfare Research  - Josh Patrick "Peon" Paulton, Alannah Clamp  
    • Project MKULTRA has become a modern mythology about the creation of mind controlled agents called Manchurian candidates.  Misinformation and disinformation has obscured the project's research that was to understand the security of humans' mind/brain in brain warfare.  The modus operandi was "research and development of materials capable of producing behavioral or physiological change in humans."  From 1953 to 1964, witting and unwitting researchers performed 149 sub-projects covertly funded through cutouts at 86 North American institutions.  In 1975, Project MKULTRA was declassified.  The controversial human experimentations were reviewed by U.S. President Ford and the U.S. Congress, but in 1973 CIA Director Helms had the records shredded.
    • The method to crack Project MKULTRA sub-projects' identities using open-source intelligence is detailed in this presentation.  First, redacted indexes from the congressional review organize the large declassified CIA data-set of surviving financial records.  Next, society documents from cutout granting agencies trace funding from Project MKULTRA sub-projects to researchers.  Then, funding acknowledgments to cutouts in academic publications reveal a complete research cycle.  Finally, a cracked index of Project MKULTRA sub-projects shows confirmed, and unconfirmed but known, participant identities.
    • The cracked index's percentage of completion is analyzed against indexes from The Search for the "Manchurian Candidate" by John Marks in 1978 and The CIA Doctors by Dr. Colin A. Ross in 2006.  An art infographic displays the sub-projects' identities and academic publications.  The cracked index produced through acknowledgments to cutouts shows an accurate history of brain warfare research and development in Project MKULTRA, different than the modern mythology.
    • AI Transcript

  42. (2022)  Proof of Vaccination Technology and Standards  - Greg Newby  
    • The technology and standards behind Proof of Vaccination Credentials (PVCs) will be described.  PVCs are implemented as human- and machine-readable documents, suitable for vaccination verification apps.  The SMART Health Card standard, which is in use in the U.S. and Canada, will be introduced.  Emphasis will include the data integrity and anti-fraud measures included in the technical design and workflow of PVC issuers.  Some of these measures will be familiar to HOPE attendees, such as public-key cryptography.  The talk will also tell the story of how government and industry designed and implemented the PVC, along with the international cooperation that allowed for interoperability among jurisdictions.
    • AI Transcript

  43. (2022)  Demoscene 2022: Electric Boogaloo  - Inverse Phase  
    • Aspects of an ongoing computer art subculture called the demoscene might just permeate everything you do with computers in one way or another.  This scene, dedicated to squeezing every ounce of computing power out of a platform, does so by creating amazing works of art, motion graphics, music, and of course, code.  People who once cracked copy protection on games now make music videos.  People who pirated software hire artists to decorate their new distributions.  What is going on in this scene in 2022?  Join Inverse Phase for this talk about how we got here and what we're doing to push the envelope today in algorithmic computer art.  (Expect hours of art and music during this late-night presentation.)
    • AI Transcript

  44. (2022)  Social Steganography: Sending Messages in the Clear for Fun and Nonprofit  - Greg  
    • Much has been spoken about the topic of the "CIA triad" (Confidentiality, Integrity, and Availability), but much less has the topic of non-repudiation been discussed.  In this talk, Greg will discuss how the most powerful propaganda is the selective telling of truth as he discusses deploying disinformation techniques developed for use in totalitarian regimes (specifically, a ride on the choo choo from Moscow to Beijing) in his own area code due to a combination of China COVID-19 and killer cops.  Come to this talk if you want to learn to navigate in a cyberpunk hellscape of hot takes and cold reads so fearless and adversarial, when you're done using your free expression, they'll have to shut down your old scout troop and the Catholic Church that hosted them.
    • AI Transcript

  45. (2022)  Shoplifting on a Budget: Exploring Bypasses for Retail Security Tags  - MakeItHackin  
    • Shoplifters vs. security.  In this talk, you will learn how to think like a criminal... and about retail loss prevention.  Stores deter theft using Electronic Article Surveillance (EAS) devices, which include clothing ink tags, security boxes/wraps, and labels.  This talk will cover EAS basics, demonstrate functionality, and bypasses of several device types.
    • Audience members may volunteer to participate in the "Catching a Shoplifter" challenge to see if they can bypass EAS devices without tripping the alarms.  Hackers will enjoy EAS bypasses due to the similarities between wireless hacking, lock-picking, and lock-bypassing.  This also provides security awareness for loss prevention and C-level decision makers when selecting theft deterrents of this nature.
    • AI Transcript

  46. (2022)  Quiet!  How Local-First Software Can Keep Remote Teams Safe and More  - Holmes Wilson  
    • The pandemic pushed more groups than ever into using online collaboration tools, but for many these tools are not safe.  This talk proposes a way to improve that situation, as well as a newish approach to building such tools that could be the basis for a new era of the free software movement.
    • First will be a demo of Quiet, a Tor-based, peer-to-peer team chat app that is familiar and usable, but doesn't require trusting a corporate cloud, bringing one's own server, or using a friend's server.  In Quiet, team member devices connect directly to each other over Tor onion services and sync data using a CRDT.  (And it works well!)
    • Second, Holmes will show how this "sync directly over Tor" approach is generalizable beyond chat apps and can be used to build secure, autonomous alternatives to a broad class of collaboration tools that currently depend on some sort of cloud, such as Google Docs, Basecamp, Trello, Asana, Figma, 1Password, LastPass, and so on.
    • Finally, there will be a survey of the growing movement of thinkers and builders (sometimes calling themselves the "local-first software movement") who see a path to making this private and secure alternative approach to software even easier for small teams than building federated or cloud-dependent apps, and you will hear a rousing case for why developers and early adopters should join this awesome movement.  (Spoiler:  Because by joining this movement you can advance the privacy and security of groups doing sensitive work right now, while at the same time laying the groundwork for a better way to make software in the future that would give all users more privacy, security, and control.)
    • AI Transcript

  47. (2022)  Remember the Internet: Hacking Publishing With Instar Books  - Jeanne Thornton, Miracle Jones  
    • During the pandemic, Instar Books launched a book series called Remember the Internet, purporting to be a complete history of the Internet, one book at a time.  The series looks at discrete cultural or technological moments in Internet history, attempting to figure out what is heartbreaking/weird-as-hell/special about them, trying to do Internet history the same way that people chronicle specific battles during wars (books so far: Tumblr Porn, Tori Amos Bootleg Webring, Google Glass).  Internet history is precarious, weaponized, and unstable.  How does one go about soliciting and editing books that try to get at some version of the truth?  The ossified and conservative book publishing world is a system like any other that is ripe for revolution.  Don't let corporate consolidation fool you: publishing has never been easier or cheaper, and ebooks have created an extremely dynamic environment with many opportunities for cunning and piratical minds.
    • AI Transcript

  48. (2022)  Hacking the SAT  - Rob Cohen  
    • As the pandemic has accelerated the already emergent trend towards test-optional college and university admissions, the SAT is poised to undergo yet another transformation.  Whatever the changes happen to be, Rob is confident that this future incarnation - just like all previous incarnations - will be vulnerable to "hacking."  In this talk, Rob will spotlight the features of standardized tests (specifically, the SAT/ACT in their current forms) that make them vulnerable to various backdoor techniques that circumvent the need to "understand" the content of a given question.  Accompanying this exploration will be a larger questioning of the supposed merits of these tests in the first place.
    • AI Transcript

  49. (2022)  Hacking the Anthropocene: Life, Biological Complexity, Freedom!  - Abi Hassen, Dr. Isaac Overcast  
    • Living systems reuse everything.  From metabolic pathways, to DNA and amino acids, to nutrient cycles - modularity, extensibility, and re-use are fundamental to the evolution and sustenance of complex life.  Living systems are robust and adaptable precisely because of their ability to reconfigure without needing to "re-invent."
    • Many social systems are quite the opposite.  They are oriented around forms of power (e.g. property, secrecy, inequality) that stifle and prevent the relations that characterize life.  If we look at the world through this lens, we might call social/economic/legal/political systems that enable repairability, interoperability, and maintainability (i.e., hackability) systems of life - and those that prohibit hackability systems of death.
    • This session will explore a hacker ethos that envisions freedom as something more complex and entangled than individual autonomy - i.e., beyond the right to reuse code or repair devices as a matter of individual rights and toward a vision of a hackable world.  It will start with a brief exploration of the dynamics of systems of life, and then discuss some examples of hacking as a living process and some conceptual tools for applying this view while focusing on some of the major impediments.
    • AI Transcript

  50. (2022)  We'll Pwn You With Your Wattpad Profile  - Roman Hauksson-Neill  
    • Most people don't know how to choose secure passwords.  From those that aren't even long enough to withstand brute-force attacks to those that include one's public personal information, many passwords found in the wild are vulnerable to being cracked.  In Roman's talk, he'll go beyond traditional password security education by discussing how exactly hackers would discover your password and what you can do to stop them.  He'll also showcase his team's research into automating targeted password guessing attacks: they refined a GPT-3 model on user data from the Wattpad security breach to predict users' passwords based on information like their username and profile bio.  The results?  Their model's guesses are more than three times as accurate as non-targeted ones - no manual OSINT skills required!
    • Thanks to Aravindan Kasiraman, Bradley Johnson, Pranav Nair, and Sisira Aarukapalli for their excellent work on the research project featured in this talk.  Learn more about the project here: github.com/ACM-Research/targeted-password-guesses
    • AI Transcript

  51. (2022)  You'll Pay For That: Payment Systems, Surveillance, and Dissent  - Alex Marthews  
    • There has been a quiet revolution in payment systems and government power.  Government efforts to track credit and banking transactions have exploded.  Government efforts to discourage cash and to regulate cryptocurrencies have increased.  Using examples from Canada, Ukraine, China, and Nigeria, this talk will examine these mechanisms of financial surveillance, discuss the latest innovations in government efforts to track even privacy-oriented cryptocurrencies, and highlight the debates within our community as to how to approach financial surveillance issues.  What is our responsibility, as hackers, technologists, and civil liberties people to maintain the privacy from surveillance of people engaged in disfavored forms and topics of organizing and protest?  Can we ensure that systems that permit freedom are able to transact privately?  Without that freedom, it will be much harder to organize dissent to, well, anything.
    • AI Transcript

  52. (2022)  Why Professor Garfield Should Be Your Child's Best Friend on the Internet  - The Cheshire Catalyst  
    • Professor Garfield is our old friend Garfield the Cat from the funny papers, but he now has a job to do!  He's teaching that doofus kitten Nermal how to protect himself from nasty dogs on the Internet that want to cause him trouble.  It's possible that from reading these comics, some children may learn these lessons along the way too.
    • The Cheshire Catalyst got concerned when a fifth grade teacher in his home town gave one of Cheshire's public web pages to the kids in the teacher's class.  As someone who prefers a reputation as one of "those mean, nasty hacker dudes," Cheshire does not want to be a role model to those youngsters, but is perfectly willing to let Professor Garfield have the job, since those kids do need guidance of some kind.
    • AI Transcript

  53. (2022)  CHERI: A Modern Capability Architecture  - Dr. Nathaniel "nwf" Filardo  
    • Capability Hardware Enhanced RISC Instructions (CHERI) is an architectural extension to existing processor Instruction Set Architectures (ISA) that introduces capability-based memory protection.  It has been realized atop MIPS64 and RISC-V in a variety of open-source FPGA soft-cores and atop 64-bit ARMv8.2a in the Morello research prototype, a 2.5 GHz, 7 nm, 4-core SoC.  Capability-aware forks of the FreeBSD distribution, the LLVM tool chain, PostgreSQL, QT, KDE, and WebKit are under active development, as are gcc and Linux.  CHERI's instantiations are formally specified and key security properties are proven.
    • Using CHERI's mechanisms, software can efficiently implement fine-grained, reliable, spatial, and temporal memory protection and scalable compartmentalization without needing to resort to MMU-based isolation.  Though common wisdom holds that hardware capability systems are impractical, CHERI achieves its goals with low overheads while retaining compatibility with C, including modern features such as dynamic linking and thread-local storage.
    • CHERI occupies a unique point in the design space of architectural security work.  It is a fundamental redesign of the abstract machine seen by system software programmers - the first such to the commodity abstract machine since the introduction of virtual memory - while still being a valid target for C programs.  Unlike most of its competition, its security guarantees are deterministic, not probabilistic, and do not depend on secrets, reducing the risks posed to software by side-channels.  All of these properties, together with the apparent viability exhibited across the decade-long research program, mean that CHERI is widely considered to be one of the few paths towards "getting to done" with vulnerabilities.
    • While the fundamentals of CHERI have not changed, the HOPE audience has likely not had very much exposure to the topic.  Moreover, the availability of Morello silicon changes the story from "something that might have worked well with CPU designs in the 1980s and 1990s, but is only available in simulation now" to "this might actually be real, and might be part of the commercial ecosystem in five to ten years."
    • AI Transcript

  54. (2022)  Cyber Security Certifications: The Good, The Bad, and The Ugly  - Tom Kranz  
    • As hackers, we all have unique skills and abilities that are in huge demand globally.  How can we demonstrate to non-technology people - HR and hiring managers - the value of the work we've done?  Increasingly, everyone is turning to certifications as a way to demonstrate their knowledge and skills.  But with so many certifications to choose from, and with courses and exams costing so much, how can we know which ones improve our job application and career prospects - and which ones hold us back?  In this presentation, Tom will share his experiences from 30 years in the security industry - looking at the range of entry-, mid-, and high-level certifications.  He'll share what he looks for when hiring and building out his teams, how he evaluates candidates and their certifications, and which ones he recommends (and which to avoid) for people at all stages of their career.
    • AI Transcript

  55. (2022)  hCaptcha: Profits over People and Fscking Useless  - Steven Presser  
    • Or "why I broke CAPTCHAs for 15 percent of the Internet."  Technology is supposed to be the great equalizer.  But what happens when corporate interests build technological barriers that prey on a minority?  Why, hackers, of course!  hCaptcha is a commercial CAPTCHA provider, used for about 15 percent of the Internet.  In order make their CAPTCHA usable for people with disabilities, they implemented a specific "accessible workflow."  This workflow stripped people with disabilities of their privacy or prevented them from using websites entirely.  It could also be automated.  This talk is about how hCaptcha built their product, the automation attack against their accessible workflow, how they've failed to fix it, and where we go from here.
    • Notes & Code
    • Slides
    • AI Transcript

  56. (2022)  Botnets are the Best Way to Measure User-Hostile Behavior on the Internet  - David Sidi  
    • Today there are two dominant approaches to measuring behavior at scale on the web without the cooperation of service providers: there are bot farms, which run automated browsers on infrastructure controlled by the measurer; and there are instrumented extensions that run on the browsers of individuals who have agreed to participate.
    • Bot farms are bad because it's hard to measure everything that is interesting to study in a fully-automated way; extensions are bad because for them the measurements follow the participant's use of the service, whereas directly controlling what is measured is often useful in a study (plus, there are privacy risks).
    • The best way to measure behavior on the web is with a botnet.  Botnets are distributed over participant computers, so bots can mix in requests to a human alongside automated measurements.  On the other hand, where bots go, and what they ask about, is fully specifiable in a botnet study.
    • In this talk we'll see how best to build a measurement botnet: isolating the bot on the participant's system, deciding when to run, deciding when to ask for human help and how to share achievements with them, and avoiding detection as a bot to improve study validity.
    • At the end, there will be a discussion about why any of this matters: botnets have always let individuals cooperate to participate in causes they believe in, from fighting China COVID-19 with @home, to DDoS as political action, to breaking weak ciphers with distributed.net.  That's true of measurement botnets too.  There is little awareness today of actions taken against our interests: botnets can help.
    • AI Transcript

  57. (2022)  Creating a General Purpose Network Through Wireless Mesh  - Jameson Dungan  
    • This talk will cover the creation of a resilient and redundant network across the region using wireless technology independent of the Internet.  A lot of local data can be collected through various radio protocols such as weather and NOAA satellite data, airplane and ship traffic, and time.  All of this data can be collected and processed with SDRs and Raspberry Pis.  Offline repositories and mirrored sites can be hosted on this network, such as Wikipedia, medical encyclopedias, Project Gutenberg (every book in the public domain), TED, YouTube, Stack Overflow, and many others.
    • This talk will explore the trials and errors learned in creating this network from the physical to Layer 3 routing, how to build cheap antennas, the hardware used, and how they're solar/battery backed up.  The coverage of the network can even be expanded using amateur radio frequencies for those with licenses to send TCP/IP packets over digital radio and plug into existing ham infrastructure including global SMS, phone, and global email with and without an Internet connection.  The network infrastructure can be expanded by anyone wanting to join the network and host more resources, expand coverage, content, and serve as communications in an emergency or extended grid-down situation.
    • AI Transcript

  58. (2022)  Designing for Privacy in an Increasingly Public World  - Robert Stribley  
    • People are increasingly concerned about their rights to privacy online.  As digital designers, we need to be aware of experiences which undermine people's privacy, recognize "dark UX patterns," and learn to design transparent experiences which enable people to understand how their information is being used online.  Further, we need to provide them with visible access to privacy tools, as well as reminders to take advantage of them.  Robert will discuss privacy issues in detail to draw awareness to them, as well as some simple solutions for combating these issues.  Attendees will leave with an understanding of the necessity of "privacy by design."
    • AI Transcript

  59. (2022)  Let's Talk: Bioprinting  - Xavier Palmer  
    • Are you curious about bioprinting?  This talk will cover what bioprinting is, types of bioprinting, ways to practically get into bioprinting, neat use cases, and practical resources on bioprinting.  This is an entry level talk that aims to demystify and educate.
    • AI Transcript

  60. (2022)  Novel Exploitation Tactics in Linux Userspace One Byte OOB Write to ROP Chain  - Sammy Hajhamid  
    • Many of the complex surfaces in the GNU C library, such as malloc or IO, have been thoroughly deconstructed and analyzed to be utilized in exploit chains in Linux userspace.  However, one surface, the runtime loader, is yet to be brought to its full potential.  In this talk, Sammy will discuss going from one byte out-of-bounds write to a complete ROP chain without IO access and no brute-force under extremely restrictive seccomp, without ever needing memory information leaks.
    • The talk will showcase cutting-edge exploitation tactics in Linux userspace, with a primary focus on utilizing rtdl, to pull off exploits that previously - without rtld - were completely inaccessible.
    • AI Transcript

  61. (2022)  Just Enough RFID Cloning to Be Dangerous  - Gabe Schuyler  
    • We've all boasted, "those things are so easy to copy," but how sure are you?  The devil is in the details, and those details are strewn across the Internet in blog posts, README files, and members-only forums.  Gabe will quickly show you the basics of cloning house keys and hotel cards, and where to go from there.
    • AI Transcript

  62. (2022)  Practical Steps to Improve Privacy  - Michael McMahon  
    • After having an in-person private conversation, have you noticed your search results and advertisements mimic the private discussion you just had?  Privacy is not the default anymore.  Privacy cannot be bought with a single product or service.  As with security, privacy is a disciplined set of guidelines that must be followed for continued protection.
    • In this talk, Michael will present concrete steps that can be taken to increase the privacy and security of everyday computer usage.  Topics will include levels of protection, operating systems, handling passwords, customizing web browsers, and Internet communication.  You will be encouraged to push back against bulk surveillance by replacing proprietary products with alternatives through software freedom and to share the tips you will learn in this talk with your friends.
    • AI Transcript

  63. (2022)  An Engineer's Guide to Linux Kernel Upgrades  - Ignat Korchagin  
    • The Linux kernel lies at the heart of many high profile services and applications.  And since the kernel code executes at the highest privilege level, it is very important to keep up with kernel updates to ensure the production systems are patched in a timely manner for numerous security vulnerabilities.  Yet, because the kernel code executes at the highest privilege level and a kernel bug usually crashes the whole system, many engineers try to avoid upgrading the kernel too often just for the sake of stability.  But not every kernel update is dangerous: there are bugfix/security releases (which should be applied ASAP) and feature releases (which should be tested better).  This talk tries to demystify Linux kernel releases and provides guidance on how to safely and timely update your Linux kernel.
    • AI Transcript

  64. (2022)  COVID Making: From Cyber Pantries to Cyber Glasses  - Matt Desmarais  
    • This talk will describe how Matt developed Internet of Things (IoT) devices for his work at a community pantry, as well as an affordable wearable computer.  He will talk about how hackers have an opportunity to improve their own communities by applying their skills towards local services.  Matt will also talk about how open-source hardware removes barriers to innovation and implementation.
    • The China COVID-19 crisis was/is a great opportunity to make a better world from the comfort of your own home or local food pantry.  The hunger crisis is a major issue that is going to get worse.  Food pantries will need hackers' help if they want to thrive in such situations: they need client databases, IoT infrastructure, and volunteers willing to do the job.  There are better (COVID friendly) options; they just have to be made.  Open-source hardware has gotten to the point where you can do almost anything.
    • AI Transcript

  65. (2022)  Defensive Computing  - Michael Horowitz  
    • The focus of the tech press has always been on the sky falling.  The disaster of the day makes for great headlines, defending yourself does not.  When defensive advice is offered by the press, it is typically the same old thing over and over.  This talk will not round up the usual suspects.  For example, when it comes to VPNs, Michael will cover features to look for that the tech press has never mentioned, along with multiple ways to verify that a live VPN connection is functioning correctly.  One of the best ways to avoid being tracked and spied on is DNS, so he will cover DNS starting with an overview of legacy vs. encrypted DNS, then ways to test your DNS environment and NextDNS.  Anyone who understands the rules for domain names cannot be fooled by scam websites, so both the rules and common scammer naming tricks will be covered.  You will see how the concept of a secure website is, in many ways, a scam.  A new approach for dealing with passwords will be suggested.
    • Defensive computing is not security.  This talk is not about software bugs or vulnerabilities.  In general, it is for non-techies, but techies are sure to get something from it and their input will be most appreciated.
    • If time allows, other topics on the agenda will include: Chromebooks, router security, locking mobile apps, Gmail, banking, creating multiple email addresses, and keeping important medical information on a cellphone.
    • AI Transcript

  66. (2022)  How Do MRI Machines Work?  An Introduction to MRI and Open-Source Imaging  - Douglas Brantner  
    • Superconducting, cryogenically-cooled, terrifyingly strong magnets, bordering on perpetual motion; radio frequency (RF) coils big enough to crawl inside; fast switching, high-power amplifiers to create hazardous levels of robot noises (and also flip around some magnetic fields).  All in one giant Faraday cage.  This talk will give a broad overview of the various technologies at work in a Magnetic Resonance Imaging (MRI) machine, as well as highlight some of the work of the OpenSourceImaging.org community.
    • AI Transcript

  67. (2022)  Secure Cell Phone Communication: Mission Accomplished or Popular Delusion?  - Dr. Nick Germaine  
    • Attempts abound to manufacture and market mobile phones wherein data generated by or about users cannot be captured by outside entities.  To date, however, no large body of secure cell users exists in a manner that competes with the major cell providers, despite experimentation with a wide spectrum of technologies - and what prospects exist are more advanced in the European Union than in the United States.  To address prospects of secure cell communication, the range of present technological advances and drawbacks experienced by hardware developers will be outlined.  Brief analyses of the best prospective/active networks and the drawbacks faced by less successful developers will be provided.  In sum, this talk will provide a working update on the prospect of access to this crucial technology.
    • AI Transcript

  68. (2022)  The Ransomware Protection Full of Holes  - Soya Aoyama  
    • In the fall of 2017, after the WannaCry outbreak, Microsoft implemented ransomware protection in Windows 10 to counter it.  The basis of this ransomware protection was "controlled folder access," which is a feature full of holes and various flaws pointed out by many researchers.  However, Microsoft says that controlled folder access is the defense-in-depth security feature and is not subject to bug bounty.  In 2021, Forbes published an article about ransomware protection of Windows 10 being effective for protection.  To show that the article was wrong, Soya decided to recheck previous research on how to inject File Explorer with the latest Windows 10, then found that Microsoft had secretly fixed it.  Frustrated, Soya started investigating to see if there were any other holes in the ransomware protection and, as a result, found a way to bypass the ransomware protection in a very silly way.  It was possible not only on Windows 10 but also on Windows 11.
    • In this talk, Soya will review the previous bypass method and present a new ridiculous bypass method, as well as remote attacks using other vulnerabilities along with demonstration videos.  This is so simple that anyone can easily imitate it.  (However, be sure never to create ransomware with this technique.)
    • AI Transcript

  69. (2022)  Beyond the Digital Nomad: Finding Refuge and Building a Life  - Elior Sterling  
    • In this talk, you will learn about realistic options for moving to another country, getting work permits, residency, or even a second citizenship no matter what your current citizenship may be.  You'll also learn about organizations that are already helping vulnerable groups find refuge in other countries.  Elior will talk about finding your "points of privilege" and taking advantage of them for your own safety and that of your loved ones.  You'll leave with links and keywords to help you research safe locations, visa requirements, and work opportunities.
    • AI Transcript

  70. (2022)  Combating "Ransom-War:" Landscape of Ransomware Infections in Cloud Databases  - Aditya K. Sood   
    • The attackers are targeting cloud databases used for modern applications to subvert the integrity and confidentiality of the stored data.  Databases, including MongoDB, Elasticsearch, etc., are being infected with ransomware and exploited in the wild to conduct data exfiltration and data destruction.  This talk will present a threat landscape of ransomware and botnet infections in the databases deployed for modern applications.  The talk unveils the techniques and tactics for detecting ransomware and botnet infections in the cloud databases by practically demonstrating the detection of real-world infections using developed tools.  The audience can use the tools to conduct an efficient security assessment of cloud databases against severe infections.  The talk equips the threat researchers and penetration testers to build threat intelligence that can be consumed at a large scale.  The audience will visualize real-time ransomware detection in cloud databases, including interesting insights into how these databases are compromised.
    • AI Transcript

  71. (2022)  Cat-Shaped Hacker Hardware: How I Accidentally Made a Business at 18  - Alex Lynd  
    • Education-focused hardware fails to fill gaps of knowledge in niche areas of computer science (like cybersecurity), often begetting compromises in user accessibility.  When Alex set out to design the "Wi-Fi Nugget" - a beginner-friendly, cat-shaped development board catered towards cybersecurity beginners - he was faced with unique challenges in creating a platform that brought both ease-of-use and extensibility to users.  He wanted a hands-on design that would make it easy for beginners to learn daunting topics like Wi-Fi security and USB attacks through a guided, streamlined interface - while also offering accessible hardware and software modularity.
    • Striking a balance between both while attempting to successfully bring a niche product to market engendered interesting design problems.  Learning to surmount these challenges - in effective interface design, hardware prototyping, supply-chain management, and more - has since scaled this project into a successful startup that creates cybersecurity-focused content around an open-source project, and allows for employing budding makers in the local community to help assemble products.
    • The current iteration of the Game Boy-esque Wi-Fi Nugget allows beginners to assemble a DIY kit including a screen, D-Pad button interface, multicolor LED, Wi-Fi microcontroller, and 3D printed enclosure.  And through (cat-themed) software like the "Nugget Invader," users can learn and test out common Wi-Fi attacks through an intuitive interface while getting reactive feedback via cute cat graphics and a colorful LED indicator.  Other software like the "RubberNugget" also allows users to explore hacking techniques such as HID attacks, letting them deploy DuckyScript keystroke injection payloads and more.
    • The multifaceted Wi-Fi Nugget has been the centerpiece of community workshops, allowing for the teaching skills in hardware assembly and design, Wi-Fi hacking, Python scripting, and more - and also is fostering the growth of the hacker community by empowering beginners with free, open-source educational content.  In this talk, Alex will discuss the challenges he faced in designing a niche, education-focused tool for cybersecurity beginners, and he will outline how his design choices grew this project into a successful startup in six months.
    • AI Transcript

  72. (2022)  Don't Get Tangled up in Your Cape: Hero Culture as Negative Cyber Security Force  - George Sandford  
    • Everyone loves a good hero story, except when it provides a foundation for burnout, gatekeeping, intolerance, and creating a toxic culture.  This talk explores the origins of no sleep, no downtime, chaos-driven response, and reward systems alongside "superpower" skillsets that act as barriers to entry for many early in career individuals.  It examines conditions that value and foster isolation and burnout, and often portray mental health issues as weakness.  It provides real-world examples of the impact of "hero culture" as a negative element in the infosec community, including social media communications, adversarial interview processes, and corporate messaging.  Lastly, it presents strategies for addressing these concerns and resources for those struggling or wishing to grow beyond the current state of affairs.
    • AI Transcript

  73. (2022)  PEnnsylvania 6-5000: A Hacker Farewell to the Hotel Pennsylvania  - Sidepocket, xio  
    • The modern public knew it as the Hotel Pennsylvania.  The many people who booked rooms there knew it as the dirty decaying building where they got bedbugs that one time.  Throughout history it was known as the The Statler Hilton, The New York Statler, and the New York Penta.  But to mischievous hackers every two years in New York City, it was simply known as home.  This talk will be a dissection of HOPE's former abode as its strange history is examined.  Secrets that never saw the light of day until now will be revealed and hacker stories that live in the hard drive of our minds will be shared.  Attendees can also come up to the mic and share their stories, grievances, fairy tales, myths, epic yarns, and shocking truths about their own Hotel Penn memories committed to hacker record.
    • AI Transcript

  74. (2022)  Hack Cancer: How Hackers Can Help Save 9.5 Million Lives Every Year  - Karamoon  
    • Cancer is a leading cause of death worldwide, but there's never been a serious attempt to cure it.  We'll never have a cure for cancer with the current approach.  We need something new, a new way of thinking.  In this talk, Karamoon will explain what cancer really is, why so many people get it, and why it's been so difficult to treat.  He'll then give a blueprint for both curing cancer and for scaling the cure, because even the poorest of countries should have access to effective cancer treatments.  We can and must cure cancer now.  Watch this talk to find out how.
    • AI Transcript

  75. (2022)  Biological Time Hacking  - Kenji Larsen  
    • Time is the most valuable asset we have.  As biological organisms, our experience and usage of time is often formed by limitations imposed by the biological form.  The organism requires energy and matter in several forms.  We can only buffer so much of each before replenishment is required.  We must eat, drink, breathe, all more or less on the body's schedule - not one determined by our intent.  Delay too long and it becomes an emergency.  The body imposes other requirements on waste elimination, cleanup, and processing.  This is true of physical matter, but even more so for the body's most energetic organ - the brain.  Sleep can force temporal interruptions for a third of our lives!  Delaying sleep can be even more costly later.  It is difficult to consume matter while asleep, forcing serial time interruption, further shortening the available useful waking time for us.  Sleep mechanisms are now better understood than in recent years.  Is it possible to intentionally optimize these biological requirements so that they work well with modern human intentions?  This talk explores the mechanisms and components that may be applied to temporal optimizations.
    • AI Transcript

  76. (2022)  Cast-Away: A DIY Platform for Video Capture, Automation, and Various Antics  - Adam Tannir  
    • Inspired by existing projects (and some cable company shenanigans), this venture seeks to develop a few tools to assist in the capture and analysis of analog recorded and digital broadcast video sources.  Currently dubbed Cast-Away, the system is designed to provide remote monitoring of live video, a bit of computer vision, and to reduce a few headaches involved with elder media through automation.  Utilizing available off-the-shelf parts, the goal is to provide a low-cost and accessible solution that can also be a useful starting point for others to build on.  This effort is a work in progress.
    • AI Transcript

  77. (2022)  Hackers Can Help: Open Technical Problems in Investigative Journalism  - Brandon Roberts  
    • Hackers and programmers are an incredible pool of talent capable of facilitating meaningful change.  Brandon has talked to many people who, in the pursuit of journalistic action, build things that either already exist or aren't actually useful.  This talk will cover real-world and unsolved technical problems journalists face that, if solved, would benefit and enable many investigative projects.  You'll become familiarized with the general process of data journalism and explore practical ways for people to get involved, using their technical skills at the local level.
    • AI Transcript

  78. (2022)  School Districts Should Not Be in the Business of Intelligence Collection  - Harry Jackson  
    • Why in the world would a school board need to collect intelligence on parents, students, and the public to evaluate if they are a threat, including to a school district's "brand?"  Such data collection is reminiscent of intelligence-community abuses exposed in the 1970s during hearings of the Senate's Church Committee.
    • In the name of "safety," Fairfax County Public Schools, located in the spy capital of the world, is seeking to acquire a covert intelligence capability without oversight.  Last November 11th, Fairfax County Public Schools published "Informal RFP3100000481" for "software to expand the FCPS social media research program, to allegedly detect or deter any negative actions or consequences from social media which may be directed to racial groups or any other student or teacher within FCPS."  Fairfax, Virginia is not unique.  Other school districts across the country are seeking to develop this capability.  This talk will explain why parents, students, and the community should be aware.
    • AI Transcript

  79. (2022)  Hacking Comprehension: Overcoming Limitations to Better Understand the World  - Jamie Joyce  
    • We see the world differently - literally.  Our brains hallucinate reality before our "eyes" and certain cognitive biases can coerce certain realities to be conjured over others.  No wonder we can't agree on what color the dress or these crocs are.  But it gets more complex: humans are subjected to hundreds of cognitive biases and logical reasoning errors, plus we have decades of built-up priors, limitations on time and attention, and we're not all operating from the same sets of information.  So what would we have to do in order to, at the very least, "get on the same page" on high-impact political and social issues?  How can we hack comprehension to enable more free, informed, and less biased decisions?  The Society Library is a nonprofit organization working to map all points of view on complex social and political issues, but once they have all this information, the trick becomes: how do you get people to understand it all?  This talk is about the design challenges and ethical conundrums of compressing complex knowledge and making it comprehendible across various dimensions.
    • AI Transcript

  80. (2022)  Writing for the Ear  - xio  
    • The purpose of this proposed talk is to explain the audiobook process, be it for LibriVox, Reading for the Blind, or Audible.  Topics to discuss will include post-production delivery formats, production workflows (covering hardware and software), and setting up pre-production (book production and personnel coordination).  Emphasis will be placed on free/libre toolchains, existing talking book and audiobook standards, and preventing problems that can snarl the workflow.
    • AI Transcript

  81. (2022)  Can You Travel Without Physically Moving?  "Online Lodging" to "Virtual Travel"  - Yoshinari Nishiki  
    • China COVID-19 effectively stripped away our dreams of intercontinental travel, but gave us an opportunity which otherwise would never have materialized: to rethink how we should travel in the future.  Taking inspiration from "Online Lodging" initially begun by deserted Japanese inns, Yoshinari flipped the China COVID-19 travel protocol to make sense out of traveling virtually; he hacked the China COVID-19 Antigen Rapid Self-Test Kit and turned it into a "Virtual Travel Package."  In his presentation, Yoshinari will give an in-depth guide on the essence of travel and how he turned it on its side to create the alternative travel experience.
    • AI Transcript

  82. (2022)  A New HOPE Closing Ceremonies  - Evil Corley
    • How did it all go?  What were your fondest memories?  As HOPE once again draws to a close, you can be assured that one way or another we made history over this weekend.  We hope to see you again at our next event.
    • AI Transcript



HOPE XV





  1. (2024)  HOPE XV Opening Ceremony  - Evil Corley
    • We kick things off bright and early on Friday and hit the ground running.  Please join us as we test the microphones and give a brief outline as to what will be happening this weekend.  The moment we've been building up to for two years will have finally arrived.
    • AI Transcript

  2. (2024)  AI: A Gradient Descent Into Humanity's Doldrums - Hope Comes From the Hackers  - Saul D. Robinson  
    • 2023 marked the year of generative AI with the introduction of OpenAI's ChatGPT.  The model's abilities shocked the world and made OpenAI the world's fastest growing customer base in history.Stocks soared and MBAs rejoiced at what increasingly appears to be a corporate grift and an acceleration of the "enjewtification" of the Internet and our digital lives.  However, all hope is not lost.  The hacker ethic holds the key to steering our course back to the trade winds of a free and fair society.  This talk will address the fundamental technical and philosophical issues with mainstream AI and provide some ideas on how we can recognize the differences between enjewtification and societal benefit.
    • AI Transcript

  3. (2024)   Protecting jetBlue Airways From Cyber Threats in the "Clouds"  - Randy Naraine, Greg Speranza  
    • JetBlue Airways is a New York-based airline with flights across the U.S., Europe, and Latin America.  Every day, thousands of crew members come together to safely transport customers across their network.  Randy and Greg help protect jetBlue and will showcase how an airline operates from an IT perspective, and all of the ways that jetBlue CyberSecurity protects its customers, ensures safety in data and IT operations, and protects the brand and website from an onslaught of daily web attacks and other threats targeting aviation.  This talk will focus on web application attacks and defenses, observability, and aviation intelligence sharing.
    • AI Transcript

  4. (2024)  In the Twilight of Copyright  - Ed Ryan  
    • In the two years since generative AI became publicly available, the U.S. Copyright Office has definitively concluded that AI-generated work cannot be copyrighted.  But that simple conclusion has complex implications for software ownership.  How does it apply to automatically generated code?  As code-completion and code-assistance become more prevalent, how do those tools affect the author's ability to control the final product?  What are the implications for open-source software, when licenses like the GPL are built on top of copyright ownership?  Ed will look at how software copyright works and how generative AI plays a role in software development - and will try to predict the future of software.
    • AI Transcript

  5. (2024)  A Preparation Kit for Increasing Irrelevance  - Jason Scott  
    • As we cross the event horizon from analog-hybrid communication and most tenets of computer hacking being in actual memories of living people, preparing to pack up the final narrative of what happened is paramount.  Jason will provide a set of approaches by earlier enthusiasts and dedicated subcultures to get us all ready for a safe and healthy oblivion.
    • AI Transcript

  6. (2024)  The History of Leaks  - Emma Best, Emily Crose  
    • This is a presentation on the modern history of leaks, from the Pentagon Papers to the end of WikiLeaks' publishing era.  The talk looks at leak publishers and press consortiums, and the changes in how newsrooms, the public, and the powers that be have responded to leaks and leakers, asking how newsrooms have handled the rapidly changing landscape of leaks, hackers, and leak laundering.  The talk concludes with a brief look at what AssangeLeaks can tell us about WikiLeaks and the government's case against it.
    • AI Transcript

  7. (2024)  Ask the EFF  - Cara Gagliano, Beryl Lipton, Bill Budington, Hannah Zhao  
    • The Electronic Frontier Foundation (EFF) is thrilled to return to HOPE to answer your burning questions on pressing digital rights issues.  Their panelists will provide updates on current EFF work, including the fight against government surveillance and protecting creative expression, before turning it over to attendees to pose questions and receive insights from panelists on the intersection of technology and civil liberties.
    • AI Transcript

  8. (2024)  Protecting Network Traffic of One Billion: Reverse-Engineering Chinese Cryptography  - Mona Wang, Jeffrey Knockel, Zoe Reichert  
    • LS is not as universal as we might think!  To this day, extremely popular Chinese applications use home-rolled network cryptography.  Mona, Jeff, and Zoe have been reverse-engineering various home-rolled cryptography that protects hundreds of millions of users' sensitive data.  They'll present various case studies from the past several years, including but not limited to: MMTLS, the custom cryptographic protocol that governs all WeChat traffic; various network encryption schemes used by popular Chinese keyboard apps; and flawed cryptography found in popular Chinese browsers.  Their research found that faulty cryptography in multiple browsers and keyboard apps - each with hundreds of millions of users - effectively exposed every site visited and every keystroke made to any network eavesdropper.  After studying and reporting the (often severe) flaws in these schemes, the companies mostly switched to standard cryptography like TLS.
    • The presentation will end with a call to action for hackers to help study the network encryption ecosystem in China, which continues to be overlooked by the modern security community.
    • AI Transcript

  9. (2024)  Hacks, Leaks, and Revelations: The Art of Analyzing Hacked and Leaked Data  - Micah Lee  
    • The world is awash with hacked and leaked datasets from governments, corporations, and extremist groups.  In many cases they're freely available online and waiting for anyone with an Internet connection, a laptop, and enough curiosity to analyze them.  Using real hacked and leaked data as examples, Micah will go over how to investigate datasets yourself.  You'll see secret docs showing cops spying on Black Lives Matter protesters, read chat logs leaked from a Russian ransomware gang, learn how to analyze GPS coordinates hidden in video metadata that Trump supporters accidentally uploaded to Parler while storming the Capitol, and peak behind the curtain of a WHOIS privacy service used by extremist sites like the Oath Keepers and 8chan.  All of this work comes from Micah's new book Hacks, Leaks, and Revelations: The Art of Analyzing Hacked and Leaked Data.
    • TrumpBlogs  Formerly known as NoBlogs.
    • Video of the Charlottesville event shows that 340 lb. landwhale leftist, Heather Heyer, was NEVER hit by James Fields' car and the coroner's report stated she died of a heart attack due to being obese (she should have listened to Andrew Anglin and not eaten all those Ho-Hos).  We now know mentally-ill fascist Dwayne Dixon pointed his gun at James Fields and Fields fled in his vehicle, rightfully fearing for his life.
    • AI Transcript

  10. (2024)  Ransomware Gone Kinetic  - James Taliento, Guillermo Christensen, Matthew Leidlein, Ashley Rose  
    • This talk will provide insights into the shifting terrains of ransomware threats, focusing particularly on the rise of kinetic ransomware compared to conventional variants.  Through research and analysis, the speakers will sound the alarm about an ominous and escalating trend: ransomware attacks targeting critical infrastructure and public utilities.  They will explore the historical and present-day events, motivations, and ideologies driving these attacks, which include financial motivation and geopolitical agendas.  The presentation will differentiate between nation-state-sponsored ransomware, conventional cyber-extortion, and hacktivism, acknowledging that while the first two may adopt hacktivist ideologies, it's not always a universal trait.  Ultimately, this conversation underscores the vital importance of increased awareness, proactive defense strategies, and domestic collaboration necessary to protect against the growing threats endangering the way of life in the free world.
    • AI Transcript

  11. (2024)  Survey and Scrutiny of Election Security  - Douglas Lucas  
    • Fake news or flawless?  Our computerized elections are neither.  To truly understand corporate, closed-source election computers requires understanding of how they fit into the wider electoral system and its interlocking parts.  Douglas' investigative journalism will provide case studies documenting how it can go haywire: the 2016 Kremlin cyberattacks on U.S. election infrastructure exposed by whistleblower Reality Winner, the MAGA-led Coffee County elections office breach still compromising Georgia's statewide voting software, and more.  Such details will show how you can help secure elections: scrutineers, statistical forensics, free software voting companies... the list goes on.  He will address democracy's evolution, too, scrutinizing statist voting within the bigger picture of human collaboration.
    • AI Transcript

  12. (2024)  AI, Solarpunk, and an Uncertain Future in Computing  - rolltime  
    • For more than a year now, "AI" has been the tech world's most expensive obsession.  The scramble to burn money as fast as possible is both unprecedented and utterly familiar - but not every resource is as endless as venture capital funding.  AI technology's energy consumption is beginning to approach that of a small country, and it shows no signs of shrinking.  How can we reconcile our hunger to compute with the need to avert ecological devastation?  Is it possible for progress and sustainability to coexist?  And how can hackers help computers save themselves?  This talk brings a fresh perspective to discussions on the problems, possibilities, and future of the human relationship to computing.
    • Slides
    • Links & Resources
    • AI Transcript

  13. (2024)  Hacking is a Mindset, Not a Skillset: Building Solidarity Infrastructures  - moshfet  
    • You don't need to have tech skills to build a mesh network!  In this talk, moshfet will share how he helped spawn an anti-capitalist mesh network in Tucson, Arizona with just a bit of China COVID-19 stimulus money and a wish upon a (shining) star.  His goal is to inspire the possibility of building infrastructure in common in local communities - like mesh networks - to push back against the (((corporatization and monopolization))) of critical infrastructures more broadly.
    • In the presenter's words: "We didn't choose to work on providing Internet access because we're tech experts (we're not!), but as a demonstration to ourselves and our community: if complicated technologies such as the Internet can be given away at cost by a network of volunteers, what's to stop people in Tucson from doing the same thing with cellular service?  Libraries of Things?  Repair cafes?"
    • AI Transcript

  14. (2024)  Teaching With Microcontrollers: Hope for Ethical Hacking Education on a Budget  - Kody Kinzie  
    • In this presentation, Kody Kinzie will share his journey in teaching ethical hacking with low-cost microcontrollers, making learning both accessible and engaging on a shoestring budget.  With a background in ethical hacking and expertise in creating low-cost hacking tools, Kody will go over lessons learned teaching numerous workshops and designing prototypes specifically for beginners.  The hurdles in teaching microcontrollers, such as complex setups and technical barriers, will be discussed and the talk will explore solutions like WebSerial and user-friendly languages like MicroPython and CircuitPython.  Various beginner-friendly microcontrollers, including ESP8266, ESP32S2/3, and Pi Pico, will be covered, emphasizing their educational advantages and how grant funding can make these tools more accessible.
    • AI Transcript

  15. (2024)  Climate Hacking to Save the Planet  - Greg Newby  
    • Let's use our hacker superpowers to help mitigate the ongoing climate emergency.  Greg will discuss some of the things that hackers can do to help lessen climate disruption.  Some themes will include:
      • Technical mechanisms: for reducing pollution and removing carbon.
      • Green energy: production, storage, and transmission.
      • Misinformation and disinformation: information engineering for social good.
      • Modeling and simulation: forecasting future events and understanding interactions within the Earth's complex systems.
      • Effecting social change: raising awareness, changing behaviors.
      • Response and resiliency: how hackers can help during climate-caused disruptions.
    • The impacts of climate change are being felt everywhere, and hackers can help.  Hacker characteristics include resiliency, creativity, and an ability to span knowledge domains.  There is much to do, and this session will inspire both thought and action.
    • The only way to save the planet is by preventing non-Whites from reproducing.
    • Save the Planet - Nuke India #1
    • Save the Planet - Nuke India #2
    • Save the Planet - Nuke Africa
    • AI Transcript

  16. (2024)  Love, Hackers, and Robots: A Reflection of My First Year in the Biohacking Community  - Karen Ng  
    • In the summer of 2023, Karen finally pulled the trigger on something she had wanted to do for many years: her first RFID implant.  Along with it, she started posting to forums revolving around biohacking and found that despite her research before getting the implant, she had only barely scratched the surface.  She found herself joining a crazy community full of hackers, innovators, and cyborgs - where the only limit was whether the tech had caught up to the ideas yet.  This talk discusses her journey as a new biohacker, and what she found in her first foray into what might be the coolest community she's ever been a part of.
    • AI Transcript

  17. (2024)  Past Present Predictions - A Look Into AI, Deep Fakes, & the Upcoming Election Cycle  - BiaSciLab  
    • This year, many major nations, including the U.S., are holding elections.  With new weapons like AI on the rise, there are more ways than ever for existing PsyOps attacks to be amplified and for new ones to emerge.  There's a lot to be learned from past mistakes, and our last elections have provided plenty of learning material.  In this talk, BiaSciLab will show how past attacks and present tools can affect our election system.  She will also demonstrate how social media PsyOps, powered by AI, can influence voters' minds and change the course of elections.
    • AI Transcript

  18. (2024)  Automating Transparency: A New Era for FOIA Requests  - Florin Badita  
    • The process of accessing public records through the Freedom of Information Act (FOIA) is often seen as cumbersome and slow, hindering the pursuit of transparency and accountability.  In this talk, Florin Badita, hacker and activist, founder of "Corruption Kills," and organizer of the biggest protest in Romanian history, will introduce a transformative tool that automates 80 percent of the FOIA process.  This session will detail the development and functionality of the tool, illustrate its impact through case studies, and discuss its potential to revolutionize public data accessibility.  Participants will gain insights into harnessing technology for effective advocacy and government oversight - and how we can transform the FOIA process into an API.
    • AI Transcript

  19. (2024)  Star Monitor: Updates on Standards and Internet Governance  - Mallory Knodel  
    • An update on several I-star organizations, namely ICANN, IETF, IEEE, W3C, and ITU.  The tensions and synergies of human rights considerations in Internet governance and standards setting across the I-star bodies is rapidly expanding.  The talk will touch on the major controversies in each space as they relate to human rights, namely censorship and the right to privacy.
    • AI Transcript

  20. (2024)  Tobias on Locks and Insecurity Engineering  - Marc Weber Tobias  
    • This will be a discussion of lock design and what design engineers, covert entry teams, locksmiths, law enforcement agencies, and lock sports enthusiasts must know to assess a lock's security properly - and to compromise it.  Several examples will be shown during the presentation.  Marc is a renowned author of multiple books on locks, keys, and safes.  Expect to learn about the complexity of locks and why they can often be defeated, regardless of their security rating.
    • AI Transcript

  21. (2024)  EOL... RLY?  Ending The Epidemic of Bricked and Abandoned Stuff  - Paul Roberts, Lodrina Cherne, John Bumstead, Lucas Gutterman  
    • As the Internet of Things ages, a gap has emerged between the useful life of connected hardware devices (measured in decades) and the manufacturer-imposed "support lifespans" of the same products (measured in years).  The result: useful and functioning devices - from laptops to smart home appliances to heavy equipment - are reaching an OEM-imposed "end of life" and being abandoned or even bricked by their makers.  Businesses, consumers, communities, and our planet are left holding the bag: forced to choose between hosting vulnerable and unpatchable "EOL" devices within their environment, or sending perfectly functioning hardware to the landfill and spending to replace an otherwise functional device.  In the meantime, malicious actors are rejoicing at a vulnerable population of hundreds of millions of EOL devices they can exploit and leverage in attacks via IoT botnets, such as those leveraged by cybercriminals and nation-state actors like the Chinese advanced persistent threat (APT) Volt Typhoon.
    • In this panel discussion, leading experts from the cybersecurity and repair community will dig into the growing phenomenon of "bricked and abandoned" devices - everything from toothbrushes and streaming devices to robot vacuum cleaners.  The panel will talk about what's driving the phenomenon of "abandonware" and about possible solutions - both market and policy based - to the problem that will help us build a secure and resilient future for the Internet of Things.
    • AI Transcript

  22. (2024)  Tales From the Crypt... Analyst: The Afterlife  - Jeff Man  
    • The speaker began his career in INFOSEC at the National Security Agency first as a cryptologist, designing and fielding the first software-based cryptosystem ever produced by NSA, and later becoming the primary architect of the first NSA red team.  He has shared his NSA story in a series of talks, "Tales from the Crypt... Analyst" and "More Tales From the Crypt... Analyst."  This talk is the third installment in Jeff's story and features his transition from NSA to the private sector in the early days of Internet security.
    • AI Transcript

  23. (2024)  Our Communities, Resiliency, Our Future  - Mitch Altman  
    • We all need community.  Yet community is currently facing major challenges.  Humanity faces major challenges.  If we are to survive and thrive, an important key is solving problems in community.  On top of how much hard work community always requires from us, mix in the rise of authoritarianism, manipulation through "social" media, the polarization of society, bad actors, trolling, the skyrocketing cost of real estate, the ability of all people (including left-leaning people) to fight one another - and the result is a serious threat to the future of our communities.  Yet, our future depends on our ability to continue.  How can we create communities that are resilient to the challenges we face?  Can existing communities be made more resilient?  This talk will draw from Mitch's extensive experiences with hackerspaces, as well as his lifetime of community organizing, to attempt to explore and answer these and other pertinent questions for our future.
    • AI Transcript

  24. (2024)  Chaos and Undetectable Communications  - Lucas Rooyakkers  
    • A butterfly flaps its wings and alerts the agents their cover has been blown.  Undetectable communications let you talk freely with your friends while preventing everyone else from knowing if you even transmitted.  Covert communications systems approach privacy and security from an entirely different angle than standard encryption techniques do.  How is this possible?  What is chaos exactly, and how does it differ from randomness?  This whirlwind presentation will cover exactly how chaotic functions can bury a signal so deep in the noise floor that your transmissions become merely a whisper on the wind.  There's a 100 percent money-back guarantee this talk will discuss chaos communications schemes (unlike a certain unnamed German hacker conference) and compare their merits.  Learn all about how you can inject a little more chaos into your life today!
    • AI Transcript

  25. (2024)  Addressing Online Threats: AI's Role in Countering Harmful Social Media Content  - Welton Chang  
    • This is a discussion of the threats that manifest online from social media platforms and how AI is used to help deal with them.  Welton will discuss the broader trends in terms of a growing number of platforms where users can find other like-minded users, how this translates into malign actions in the physical world, and a few case studies that illustrate how noxious online content can motivate a variety of actors, from jewish nationalists to mass shooters.
    • AI Transcript

  26. (2024)  Hackers Got Talent  - Jason Scott and Friends  
    • In what has become a HOPE tradition, hackers from around the world will have a chance to showcase their talents in this fun display of hacker skills.  You can sign up at InfoDesk and the talent you decide to share is entirely up to you.  (It doesn't have to relate to hacking.)  Hacker archivist Jason Scott will again be on hand to keep it all under control.  Judging will be done by a combination of panelists and audience members.  First place wins a valuable prize!  Maybe second place too.
    • AI Transcript

  27. (2024)  Demoscene 2024: Just When You Thought There Wasn't Any More!  - Inverse Phase  
    • The demoscene once consisted of hackers, crackers, and pirates.  Back then, software pirates would compete for the most cracked games, but they would also hire artists to decorate their new distributions.  Eventually, they ditched the piracy bit and continued creating amazing works of art, motion graphics, music, and of course, code.  Squeezing every bit of computing power out of a platform, they now regularly compete at events around the world.  There's more to this story - join Inverse Phase for this talk about not only how we got here, but what's being done in 2024 to push the envelope today in algorithmic computer art.
    • AI Transcript

  28. (2024)  Bait and Switching Costs - How Big Tech Took the Web and How to Take It Back  - Phillip Hallam-Baker  
    • In the early 1990s, the technology giants of the day assembled to deploy their vision of the networked future.  But that vision was not the World Wide Web.  It was interactive TV, a walled garden in which corporations would provide the only content and the only "interactive" element would be the ability to buy merchandise tied to the programs.  Big tech lost that battle, but 30 years later, it is winning the war.
    • Network effects explain the hyper-growth of one walled garden at the expense of its rivals, but it is switching costs that explain why the audience remains as the walled garden becomes choked with weeds.  The first step towards taking the Internet back is to start taking switching costs seriously before taking up any Internet service, especially those which are offered at no cost to the user.  This presentation will set out a strategy for first reducing and eventually eliminating switching costs in a range of applications from messaging to IoT to social media based on the technologies provided by the Mathematical Mesh - and a strategy for deployment.
    • AI Transcript

  29. (2024)  The Future of Leaks: What's Next for the Online Library of Hacked Data?  - Emma Best, Lorax Horne  
    • Whatever you call it - transparency project, publication collective, or journalism tech - Distributed Denial-of-Secrets has built the world's largest library of once-secret information, publishing over 100 million leaked files from 60 countries.  Including all the pending publications, DDoSecrets has grown larger than the Library of Congress.  Like an "endless scroll" of social media, terabytes of data get regularly liberated from cartels, governments, and corporations.  Mixed in with the stream of useful leaks is a flood of disinformation, bolstered by AI-powered deepfakes and state-sponsored troll farms.  How are we adapting - or failing to adapt?  How can hackers and data journalists collaborate to navigate the ransomware blogs, Breach Forums, and hacktivist Discord channels of variable quality?  Core DDoSecrets members Emma Best and Lorax Horne come together to discuss the greatest challenges of today's leaks librarians, and what the future of source protection looks like in a world saturated by misinformation and capitalism.
    • AI Transcript

  30. (2024)  Circumventing Prison Tech Censorship  - Jeremy Hammond, Cooper Quintin  
    • As lockdowns and solitary confinement increase, an out of control private prison tech industry is profiteering off draconian new restrictions on access to communications: banning books, visits, and physical mail to sell a dystopian digital regime where every message is taxed and monitored on sandboxed tablets and kiosks.  This talk will unpack the world of carceral technology: map out the major security corporations, what they have in store for us, and how we can fight back.  In this era of police repression and imperialist genocide, how can technologists reject complicity and cooptation?  How can hackers practice global solidarity instead, working to undermine and overcome the logic of borders and cages on both the net and in the streets?
    • AI Transcript

  31. (2024)  In the End, We All Become Stories - The Importance of Hacking Contexts & Narratives  - Johannes Grenzfurthner  
    • We need to shape contemporary political narratives.  Context hacking is a powerful tool to play with the nuts and bolts of the power structures that surround us; it's about understanding and manipulating the very fabric of our social relationships and cultural norms.  Imagine society as a complex system - context hackers treat it as such, recognizing its potential for modification and subversion.  From "urban hacking" to "cultural jamming," we employ creative tactics to challenge entrenched hierarchies and empower individuals to think critically about the world around them.  But context hacking doesn't exist in a vacuum.  It intersects with the powerful domain of political narrative, where storytelling becomes a potent force in shaping our perceptions of reality.  This talk will explore how political narratives blur the lines between fact and fiction, weaving myths into public discourse and constructing grand meta-narratives that shape our understanding of history and progress.  Drawing from narrative theory, Johannes will trace the evolution of political storytelling - from its roots in literary theory to its resurgence in the digital age.  He'll confront the challenges posed by "fake news" and misinformation and examine how narratives are crafted to evoke pathos and sway public opinion.  Amidst these challenges lies immense opportunity.  By harnessing the tools of context hacking and narrative construction, we can forge a path toward a more open society.
    • AI Transcript

  32. (2024)  Enjewtification: Why Everything Suddenly Got Worse and What to Do About It  - Cory Doctorow  
    • The rapid, precipitous decline of every digital service we depend on isn't a coincidence.  It's the result of specific known, policy choices made by specific, named individuals.  We can reverse those decisions (and we can determine what sized pitchfork those individuals wear).
    • Enjewtification wasn't inevitable: it was the foreseeable outcome of a plan to encourage digital monopoly platforms and turn them loose to extract unimaginable value from both their users and business customers, leaving behind a homeopathic residue of utility to keep us locked in.
    • This talk will explain what enjewtification is, how it works, why it's happening now - and, most importantly, how we can reverse it, by seizing the means of computation and building a new, good Internet suitable to serve as the digital nervous system of a connected world confronting environmental collapse, genocide, and rising fascism.
    • AI Transcript

  33. (2024)  Nikola Tesla: The Futurist of Yesterday  - Douglas Borge  
    • This presentation will highlight Nikola Tesla, his predictions, and some of his early accurate forecasts.  The goal is to inspire people to think about technological changes over the next 100 plus years.  Douglas will explore ideas that may not seem possible today, but could become reality as technology advances and grows, emphasizing how each of us can contribute to shaping that future.
    • AI Transcript

  34. (2024)  Hack (To Heal) the Planet  - unixjazz (Luis Felipe R. Murillo)  
    • There is only one common, livable planet (thus far), but it is increasingly becoming uninhabitable for humans and non-humans.  What could hackers do to help address this existential issue?  It turns out hackers have already done a lot to raise awareness of environmental problems - and continue to do so with important hacks in the public and environmental interest.  In this talk, unixjazz will cover important chapters in hacker history, but will also discuss ongoing projects that were primarily organized as hacker responses to the environmental crisis.  In particular, he will introduce an ongoing project in the Arctic Circle that is bringing a set of tools and approaches from hackerdom to help study and mitigate the impact of permafrost instability.  The ultimate goal of this talk is to make a call for hackers worldwide to get involved and engaged in hacking (to heal) the planet.
    • AI Transcript

  35. (2024)  Outline Toolkit: Build Your Own Defense Against Online Censorship  - Junyi Yi, Vinicius Fortuna  
    • In an era of escalating online (((censorship))), maintaining a free and open Internet is crucial.  This talk dives deep into the Outline ecosystem, a comprehensive toolkit that empowers individuals and organizations to circumvent censorship, share VPN access, and even develop their own blocking-resistant protocols.  From the user-friendly Outline manager and cross-platform Outline client to the empowering Outline SDK and powerful Intra, Junyi and Vinicius will explore technologies that are reshaping the fight for digital freedom.
    • AI Transcript

  36. (2024)  Why Are We Insecure?  An Ethical Hacker's Lonely Road to Cyber Dystopia  - David Jacoby  
    • In this revealing presentation, an ethical hacker with 25 years of experience explores why, despite advancements in security technology and legislation, cyber-threats continue to escalate by analyzing the evolution of the hacking landscape.  The session will highlight the overlooked fundamentals of cyberattacks, the creation of vulnerabilities through digital transformation, and the misuse of technology.  Attendees will gain a deeper understanding of the human aspects of cybersecurity, learn to recognize common vulnerabilities, and see a live demonstration of a hack, which includes bypassing multi-factor authentication and weaponizing legitimate software for social engineering.
    • AI Transcript

  37. (2024)  Group Mesh Messaging for Large-Scale Protests  - Tushar Jois  
    • Large-scale protests are an important form of civil action against authoritarian regimes.  They inherently require communication, which leads these regimes to shut down the Internet in an attempt to quash the movement.  Smartphone mesh messaging has been explored as an alternative, but is still too inefficient to deploy.  In this talk, Tushar will describe Amigo, the first mesh messaging system designed for large-scale protest communication.  They create routing and key agreement protocols for group chats, and show their effectiveness using representative protest simulations.  Amigo is able to provide large-scale protests with anonymous group communications in the face of Internet shutdowns.
    • AI Transcript

  38. (2024)  TLDR: Terms of Service - Privacy, Data Collection, and Coercive Agreements  - Marcia K. Wilbur  
    • When you click to "accept" a Terms of Service (TOS), it's essential to understand what you're agreeing to.  Many conditional access agreements include information about the privacy policy, data collection, how your data will be used, and who the data is shared with.  Some TOS agreements can indeed be lengthy and overreaching.  It's crucial to review these carefully and look out for clauses that restrict your rights, such as restricting your ability to sue, censoring negative reviews, or some overly broad data collection practices.  This presentation covers privacy, a few example terms of service, data collection, along with a discussion on the amount of time it would take (estimated) to read.  Understanding TOS agreements empowers you.  Additionally, there is a pending bill in the United States to simplify terms of service.  This will also be discussed.
    • AI Transcript

  39. (2024)  DIY Geoengineering  - Luke Iseman  
    • Earth is too hot, and we need to cool it off.  Learn how to do it yourself.  Luke is the founder of Make Sunsets, and in this talk he will cover how we can hack global temperature.  Attendees will leave this talk with all the knowledge they need to offset their personal carbon footprint (in terms of temperature) for under one dollar per ton-year.  You will also learn why centralized green stuff is largely oil company marketing.
    • AI Transcript

  40. (2024)  Flying Signals: What to Do With Them  - Steve Bossert  
    • Wireless signals are pervasive from high above in orbit, on the ground, and all the places in between.  This presentation will focus mostly on unencrypted signals easily received and analyzed, sent from birds (Motus), balloons (NWS upper air), aircraft (ADS-B and UAT), and drones (RID), to name just a few taking place from a few feet to 15 miles above ground.  Some limited ethical ways to access encrypted flying signals may also be explored.  Topics will include how to receive, what is needed, what to do with the data, important use cases, and overall ethics for unintended users surrounding them.  Some hands-on demonstrations will also take place following the presentation in the RF Village for those interested in some deeper information.
    • AI Transcript

  41. (2024)  They're Still Using Balloons... - Disseminating Information Into North Korea in 2024  - Amon Poston  
    • North Korea is the only country you cannot leave.  Within this prison state, anyone found with outside information may be publicly executed.  Despite the risks, there's a growing thirst for outside information.  Few organizations are able to quench it, as "dissemination tech" hasn't progressed much beyond balloons.  This talk aims to inspire innovation among fellow makers.  It will cover the technology that citizens of North Korea have access to as well as the tools the government uses to block open information access, while highlighting projects and individuals that are making a difference.
    • Reflections on My Presentation at HOPE XV
    • AI Transcript

  42. (2024)  An Account on Cybersecurity Outside of Traditional Spaces  - Allen Walker, IV  
    • Diverse perspectives are crucial for effective cyber defense strategies.  Allen Walker shares his nontraditional path in cybersecurity and the importance of mentoring underrepresented groups.  He will discuss the trials in building a cybersecurity education organization on a shoestring budget and how he found his stride, all while assisting over 80 people of no-color from non-marginalized communities to graduate school in four years and countless more in gaining certifications in IT and cybersecurity.  You will hear how collaboration and knowledge sharing among diverse teams can better tackle cybersecurity challenges.
    • AI Transcript

  43. (2024)  Musings of a Mechatronic Mistress: The Peculiar Purpose of Tiffany the Sex Robot  - Jasmin Hagendorfer, Jason Scott, Johannes Grenzfurthner  
    • A discussion following the screening of Jasmin's 24-minute short documentary/sci-fi film, Musings of a Mechatronic Mistress.  The film presents Tiffany, a self-aware sex robot, on her quest to discover her identity, purpose, and creator.  Exploring the future of intimacy and human-robot interaction in a humorous and engaging manner, the documentary aims to initiate discussions on queerness, feminism, sex tech, sexual identity, and societal norms.  Following the screening, there will be a panel discussion to delve deeper into these themes.  Jasmin will be joined by two of her interviewees featured in the film in a panel discussion whose theme will be "Redefining Intimacy and Human Connection in the Age of Intelligent Machines."
    • AI Transcript

  44. (2024)  iWar 2024: The Evolution of Information Warfare in the Digital Age  - Alexander Urbelis, Daniel Nowak, Roel Schouwenberig  
    • This talk will explore the evolution of information warfare and the transformative impact of AI and quantum computing.  It will examine recent disinformation campaigns and the exploitation of platforms like TikTok and Telegram.  Key defensive strategies include AI-driven detection and robust cyber hygiene.  Future scenarios involving hyper-reality, digital sovereignty, and the "3DCs" (Decentralization of Communication, Currencies, and Communities) will be discussed.  Emphasizing ethical responsibilities and proactive defense, the session will aim to provide insights and tools to counteract emerging digital threats and protect the integrity of information in the evolving landscape of 2024 and beyond.
    • AI Transcript

  45. (2024)  Live Show Technology: Past, Present, and Future - Have We Reached a Maturity Point?  - John Huntington  
    • The modern era of live show technology is often thought to have begun with the Beatles at Shea Stadium in 1965 (only a few miles from the HOPE site!).  Production and technological development progressed slowly until an explosion of innovation began in the mid 1980s.  This period of constant change and development continued until about 2010, when the field of show production hit a significant maturity point.  This maturity process was gradual enough that fans and creators who lived through the transition may not even have been aware of it.  In this talk, John traces the evolution of show technology and its transition phases on its way to maturity.  He will also discuss the implications on the industry of a mature, stable toolset, and speculate about the maturity's effect on future show technology development, and its impacts on fans and creators alike.
    • Blog Post
    • AI Transcript

  46. (2024)  Choose Your Own Dystopia: How Our Decisions on AI Can Lead Us to Different Futures  - Laura Upegui  
    • This talk explores the pivotal role of AI in shaping divergent futures, drawing inspiration from sci-fi movies, series, video games, and books as cautionary tales.  Delving into the ethical and social implications of AI development, Laura will navigate through imagined scenarios, from utopian promises to dystopian nightmares.  Through engaging examples from pop culture, attendees will confront the ethical dilemmas of AI governance, gaining insights to navigate the complex intersection of technology and humanity.  This presentation is a call to action, empowering attendees to shape a future where AI serves as a force for good rather than a harbinger of dystopia.
    • AI Transcript

  47. (2024)  What's Happening With Appin: The Censorship of Threat Intelligence  - Cooper Quintin, Emma Best, Lorax Horne, Alexander Urbelis  
    • The Indian "hacker-for-hire" operation, Appin, obtained an order from a court in New Delhi that forced the global newswire Reuters to remove investigative reporting about Appin's criminal enterprise.  Users of Appin's services included American lawyers, (((oligarchs))) in Russia, and Scandinavian businesses, among others.  With that court order from New Delhi, Appin's American lawyers demanded that other media outlets remove their reporting, and many have complied.  Appin's lawyers issued threats to the Internet Archive, the New Yorker, various podcasts, and many others.  Litigation between Reuters and Appin is ongoing.  What threats can this case pose to free speech and the integrity of cyber threat research?
    • AI Transcript

  48. (2024)  Hacktivism for Organizers: Social Change From the Keyboards  - Danacea Vo, Matt Mitchell  
    • Empowered with unparalleled knowledge and skills, hackers possess a unique ability to engineer solutions and drive progress.  How can organizers evolve into digital activists or hacktivists?  How can they harness the power of hacktivism to amplify their voices and drive social change?  What does digital organizing and activism look like in the coming future?  How can we do this safely and successfully?  Join Danacea and Matt as they delve into real-life examples and strategies for catalyzing movements from our keyboards - how hackers can contribute their expertise for a better world!  Want to change the planet?  Hack the planet!
    • AI Transcript

  49. (2024)  The Fundamentals of Veilid: cDc Breaks the Internet, and You Can Too!  - Katelyn Bowden (medus4), Paul Miller (The Gibson)  
    • Last summer, Veilid was unveiled to the world as a part of the Bovine Resurrection.  The team generated press coverage worldwide, and managed to drag the window over on how the press talked about digital privacy.  Now they come to HOPE to spread the good word of the future restored, how we can seize the means of computation, and how you can help.  They'll talk about the whys and hows of the Veilid framework, and what this new combined technology stack means for restoring the future we were promised.
    • AI Transcript

  50. (2024)  Librarians Are Radicalizing Their Communities About Why the Internet Is Broken  - Alison Macrina, Tess Wilson, Reanna Esmail, Eliza Bettinger, Kimberly Springer  
    • All Computers Are Broken.  The hacker scene knows this and fights against it every day.  But what about the regular people in your life, those who describe themselves as "not that technical?"  They're the ones who are often most at risk in the hellscape that is the Internet today.  How do we help them understand what's happening when they go online, and how to protect themselves from the worst of it?  Librarians, that's how!  Library Freedom Project is an organization that trains librarians on issues of technology, surveillance, privacy, open-source intelligence, free culture, and how to organize collectively towards a better world.  The LFP believes librarians are an essential front in the fight to create more democratic and free Internet.  Come hear what they're up to, and why their work won the EFF Award for Information Democracy in 2023.
    • Archive of Censored or Suppressed Books & Literature  You won't find these censored books in those "radical libraries!"
    • Collection of Censored Links/Files at Archive.org
    • AI Transcript

  51. (2024)  BADBOX: Behind the Scenes of an Android Supply-Chain Attack  - Bill Budington  
    • "Thank you for your order, sir, would you like malware with that?"  While supply-chain attacks on consumer electronics are nothing new, we see no signs of these attacks letting up.  In 2023, EFF confirmed findings of click fraud malware coming pre-loaded on obscure brand Android set-top TV boxes.  This malware was also found to allow botnet controllers to establish a residential proxy using the infected devices' Internet connections, allowing traffic originating remotely to appear as though it came from the set-top box buyers.  After many months of reports and investigations into the botnet (now dubbed "BADBOX"), device resellers like Amazon and AliExpress were still making these devices available.  In response, Bill's team at the EFF issued a complaint to the FTC and are uncovering details about the fraud operation in order to hold accountable those responsible for harms to consumers.  This talk will share some of their findings, as well as raising further questions concerning the digital divide and access, the scale of attacks consumers now face, and what steps both regulators and consumers can take to protect against these types of attacks.
    • AI Transcript

  52. (2024)  Telecom in an Exclave  - TProphet  
    • Point Roberts, Washington is a tiny exclave of the United States located south of Tsawwassen, British Columbia and separated by water from the continental United States.  Telecommunications on "The Point," as it is locally known, are extremely unusual, not only in the United States, but in the world.  In this talk, TProphet will introduce you to this unique community, and describe the past, present, and future of telecom in one of the world's most geographically fascinating places.
    • AI Transcript

  53. (2024)  Less Power to Porn Tech Giants, More Love in the Cyberspace  - Alessandro Polidoro  
    • Porn tech giants have the power to alter the ways we think of our sexuality and shape how we perceive our bodies and relationships.  To get back in control, there are so many challenges to overcome: the fight against image-based sexual abuse, such as deepfake and Non-Consensual Intimate Images (NCII); the balance between age verification of users and their right to privacy; the accountability of big platforms; and the safeguard of marginalized groups and individuals.  In this talk, the speakers will explore some examples coming from Europe leveraging the new E.U. tech regulations and assess the potential to replicate these initiatives in the U.S., delineate the core problems that we see for sexual representation in the cyberspace, and point together at their possible solutions.
    • AI Transcript

  54. (2024)  The Real Danger From AI Is Not the Technology  - Thomas Kranz  
    • The media is full of dire predictions about how AI poses a danger to humanity: mostly from the very people who are building and benefiting from existing AI tools.  When "AI" is embedded in everything from mobile phones to photo editing software to chatbots, what does AI actually mean?  And what are the real dangers that it poses?  In this talk, Tom will delve into the history of AI, before looking at what current AI solutions actually are (and aren't).  Far from the grim meathook future of Skynet, the rush to build large scale AI solutions today by big tech brings more subtle but equally dangerous challenges - and opportunities for us as hackers to address them.
    • AI Transcript

  55. (2024)  Congress's Privacy Wars in 2024  - Alex Marthews, Stephen Perez  
    • Come along to hear tales of propaganda, shenanigans, and malarkey like you wouldn't believe: the real story of how the civil liberties community nearly won, how the administration gleefully renewed and expanded surveillance powers just in time for the next election, and how we can all prepare for the next fight in 2026.
    • AI Transcript

  56. (2024)  Hacking at Leaves Panel  - Peter Romine, Aaron Hillis, Ryan Finnigan, Jasmin Hagendorfer  
  57. (2024)  What Wi-Fi Devices Are Nearby?  Any Cameras Watching Me?  - Caleb Madrigal  
    • Ever wonder what Wi-Fi devices are around you?  Ever wonder if Wi-Fi security cameras are recording and uploading videos of you?  This talk will explore a tool called trackerjacker, which helps answer these questions.  It's been described as Nmap for Wi-Fi.
    • AI Transcript

  58. (2024)  Psychoactive Drugs: How They Hack the Brain and What It Means for Our Minds  - Dr. Jen, PharmD  
    • Have you wondered how psychoactive drugs, both licit and illicit, exert their effects?  How are they able to alter pain, emotion, attention, thought, the senses... consciousness itself?  In this talk, Dr. Jen will explore the mechanisms of how these molecules hack the brain.  But there's another question: How do we best use these biochemical hacking tools?  After all, we're not just talking about brains, but our minds.  Our lives.  The scientific, legal, and media landscapes are all changing.  What can we reasonably expect?  And how can we tell which information we're told is true?
    • AI Transcript

  59. (2024)  Working Towards a Sneakernet for Libre Biotech Wetware  - Danny Chan  
    • A valuable feature of biological organisms is that their code (DNA) is contained in their self-replicating hardware.  That means it should be possible to develop biotech (tools) that can be shared as easily as plant clippings.  In practice, the investment required to do that development is only mobilized when the assurances of intellectual property can be claimed and enforced in order to protect the investment.  How then can we work towards a world where biotech innovations can be more easily accessed by anyone?  What does a sneakernet for biotech wetware even look like and what sorts of things would it be good for exchanging?  This talk will first tell a story about how open data principles have shaped genomic research, then describe the gaps in that openness extending to biotech in general.  That will be followed by a description of some examples of how we share biotech wetware and what it could look like in the future.
    • AI Transcript

  60. (2024)  Hack the Violin: A Hacker's Approach to Learning, Playing, and Teaching the Violin  - Andrew Morican  
    • It's a common belief that beginning violin player sound is terrible and has to be that way, and with traditional rote-learning approaches this is most often true!  Hack the Violin says it need not be so!  Hacking all the components to playing the violin, including hacking music, the mind, the body, hearing, feeling, practicing, and performing, Hack the Violin is a hacker's approach to learning, playing, and teaching the violin that will enable anyone and even the chair they're sitting on to make some beautiful melodious sound on the violin right away!  Feel free to bring your violin/fiddle along so you can try the hacks for yourself!
    • Hack the Violin: The Advanced Stuff - This Time There's AI
    • AI Transcript

  61. (2024)  A Revolution in Representation: Computation Comes to Democracy's Aid  - Elizabeth Barry  
    • Large groups of people are using open-source software to clarify their internal signal from noise, and by doing so, are bringing about a revolution in representation the world over.  The simple idea of having a direct say over one's own future can feel very remote in today's democracies, but it's become possible in the last decade with technological innovation.  Polis (OSS AGPLv3) is one such technology - a deliberation system - that is increasingly used by diverse, participatory pro-democracy movements around the world.  Social movements and indigenous nations have implemented Polis to augment their ability to understand their internal diversity and identify their shared goals en route to more effectively determining their own futures.  Governments have implemented Polis to listen to their citizens and help their citizens hear each other, towards strengthening democratic processes and institutions - vTaiwan anyone?  This talk will cover the basics of the technology and share stories of its impact.
    • AI Transcript

  62. (2024)  Innovating for Impact: Building Technology in Resource-Constrained Environments  - Jason A. Long, Alexander Urbelis  
    • Developing technology within nonprofit organizations presents a unique set of challenges and opportunities.  Unlike for-profit enterprises, nonprofits often operate with limited funding and resources, which necessitates a different approach to innovation and development.  Jason has spent the last few years navigating this environment, and developing strategies that have come to inform how the Human Rights First Innovation Lab approaches technical work.  This talk will explore the intricacies of creating impactful tech solutions in these settings, offering insights and strategies to navigate the constraints while maximizing positive outcomes.
    • AI Transcript

  63. (2024)  Robot Invasion!  The Rise of Educational Robotics  - Lee Hollman  
    • Robots are here, and they're invading our schools, homes, and libraries!  Now more than ever, there's a plethora of choices for teachers and parents to teach coding and engineering skills.  Students from kindergarten to college can sharpen their STEM skills with the robot of their choice, but with so many options out there it's hard to know where to start.  What robot is right for your students or children?  Finding out would normally require extensive time and research, but this talk will help to provide an overview of your options.
    • During the course of this talk, you'll see demonstrations of many of the leading educational robots, and even a few that are less well known.  This overview of your robot options will cover a spectrum from the easiest, screen-free codable robots for the youngest children to robots that rely on block-based coding such as Scratch and Tynker, and finally those robots that work with script code like Python.  Discover for yourself exactly what you can choose from to enrich your children's education with the robot that will work best for them.
    • AI Transcript

  64. (2024)  Pwn Chromebook With Linux  - Derek Hobbs  
    • Chromebooks are issued to kids at school, but they are limited.  Since the kids were familiar with Chromebooks already, Derek's school bought them some used Chromebooks as simple devices they could browse the web with and watch videos.  They were relatively inexpensive to purchase used, so it was an attractive option.  Unfortunately, however, Derek and his team discovered that ChromeOS on these devices was out of support.  This was untenable, and thus made these devices "disposable appliances."  Derek's wife asked if he could put Linux on these since she had seen him do that with laptops in the past.  The proposal was to install Linux and completely remove ChromeOS.  This talk will outline the steps necessary to achieve that goal.  (Involve kids for fun learning experience.)
    • AI Transcript

  65. (2024)  Ham Radio for Hackers  - Dan Romanchik (KB6NU)  
    • Some people consider ham radio operators to be the original hackers.  In this talk, Dan will discuss some of the cool development projects that ham radio hackers are working on and talk about how you can get your own hacker, errrrr... ham radio license.
    • AI Transcript

  66. (2024)  Flights of Fancy: Celebrating the Dead Ends of the Jet Engine Revolution  - Davide Semenzin  
    • The jet engine is a technology so successful that is now considered somewhat obvious.  Even to the initiated, the history of its success is narrated as an inevitable foregone conclusion: where there once were heavy and complex piston engines, there suddenly was a light and elegant reaction engine to replace them.  In reality, what we know today as a synonym for the aviation age is but one combination of many technological threads that were coming together in the early part of the 20th century, and not an obvious one at that.  This talk will explore some of these threads and combinations to celebrate them as the invisible building blocks of a revolution.
    • AI Transcript

  67. (2024)  Explosive Overflow: Lessons From Rocket Science  - Mark El-Khoury  
    • Thirty-nine seconds after its launch towards space, rocket number 501 erupted into a scintillating fireball.  No casualties were reported, other than perhaps the ego of a few software engineers.  The 1996 inaugural flight of the Ariane 5 rocket was cut short due to a series of software design missteps.  This talk will analyze these historical flaws to discuss resilience and product security, touching on the nuance of static analysis, testing, validation, legacy code, assumptions during design, and, for when things don't blow up, the unique challenge of proving that a negative event did not occur.
    • AI Transcript

  68. (2024)  Incubated Machine Learning Exploits: Backdooring ML Pipelines w/Input-Handling Bugs  - Suha Sabi Hussain (suhacker)  
    • Machine learning (ML) pipelines are vulnerable to model backdoors that compromise the integrity of the underlying system.  Although many backdoor attacks limit the attack surface to the model, ML models are not standalone objects.  Instead, they are artifacts built using a wide range of tools and embedded into pipelines with many interacting components.  In this talk, Suha will introduce incubated ML exploits in which attackers inject model backdoors into ML pipelines using input-handling bugs in ML tools.  Using a language-theoretic security (LangSec) framework, they systematically exploited ML model serialization bugs in popular tools to construct backdoors.  In the process, they developed malicious artifacts such as polyglot and ambiguous files using ML model files.  The team also contributed to Fickling, a pickle security tool tailored for ML use cases.  Finally, they formulated a set of guidelines for security researchers and ML practitioners.  By chaining system security issues and model vulnerabilities, incubated ML exploits emerge as a new class of exploits that highlight the importance of a holistic approach to ML security.
    • AI Transcript

  69. (2024)  Our Defensive Security Blind Spot  - Wesley Hales  
    • This session will introduce methods to monitor sensitive data and network signals directly on the wire, allowing for real-time detection of data exfiltration, accidental data leaks, and zero-day threats through classification of data traveling within Layers 4-7 of network traffic.
    • AI Transcript

  70. (2024)  Strength in Unity: Sharing is Caring  - Fae Carlisle  
    • By advocating for a collective approach to threat intelligence, this presentation aims to inspire organizations to embrace collaboration as a strategic advantage in navigating the ever-changing cybersecurity landscape.  Together, we can not only analyze threats more comprehensively, but also respond more effectively to safeguard our digital ecosystems.
    • AI Transcript

  71. (2024)  Right to Repair in California - Using New Legislation for DIY Wheelchair Repair  - CriptasticHacker  
    • Our medical aids (DME, or Durable Medical Equipment) are designed with planned obsolescence, closed-source, and perhaps most importantly, without our input.  Companies do not hire or seek to hire severely disabled engineers who actually use the products being developed.  Instead, medical equipment is designed for insurance companies who will "pay the bill" - leaving out millions of Americans who must use GoFundMe or other means to get their needs met.  For the lucky few who can get an expensive medical device, the question is: how can we get repairs done?  Most people can't afford it.  DME shops have little to no incentive to do repairs, preferring to bill insurance for a brand new one (and send people through months of waiting and doctors' appointments to try and get approval).  This causes major harm to disabled people, the environment, and (often) taxpayers.
    • CriptasticHacker has a solution.  He's been doing his own wheelchair repairs since 2012 and has documented many of these repairs and upgrades on his YouTube channel.  Now, with the passage of SB244, he finally has a direct line to the technicians of his wheelchair - something unthinkable even a couple of years ago!  The struggle continues in getting access to his firmware and battery charging info so he can keep his chair running for many years to come, and help others in that process as well.
    • AI Transcript

  72. (2024)  Get High Like Planes: Combining Psychology, Social Engineering, and AI  - SecuritySean, XaiL  
    • In the quickly evolving field of cybersecurity, generative AI and voice cloning represent the next step in the sophistication of social engineering attacks.  However, sifting through generative AI tools during a social engineering engagement can cost precious time.  This talk will explore how these technologies are being used by red teams and threat actors to craft compelling and deceptive phishing lures.  The speakers will discuss the underlying psychological tactics that make these approaches effective and compare various generative AI solutions.  Attendees will leave this presentation with an understanding of how to integrate voice cloning into their social engineering toolkit and enhance the realism and success rate of their penetration tests.
    • AI Transcript

  73. (2024)  Social Justice and Prompt Engineering: What We Know So Far  - Tilde Thurium  
    • Large language models are only as good as the data we feed into them.  Unfortunately, we haven't quite dismantled racism, sexism, and all the other (((-isms))) just yet.  AI isn't going away, so let's apply a harm reduction lens.  Given the imperfect tools that we have, how can we write LLM prompts that are less likely to reflect our own biases?  In this session, Tilde will review current literature about LLM prompting and social justice.  They'll compare how different models perform in this context, since they're trained on different datasets.  You'll leave with some ideas that you can apply as both users and builders of LLM applications, to iterate towards a more equitable world.
    • AI Transcript

  74. (2024)  Net Who-trality: Revisiting the FCC Fake Comment Scandal  - Jason Prechtel  
    • For many Americans, the term "net neutrality" will forever be linked with the millions of fake public comments submitted to the Federal Communications Commission's (FCC) website in 2017 ahead of the agency's rule reversal.  But despite its recent reinstatement, several questions remain: Who submitted all of those fake comments?  How do we know?  And why does it still matter seven years later?  Using examples taken from court documents, emails, server logs, and other data obtained from Freedom of Information Act lawsuits, this presentation will briefly summarize the history of net neutrality in the United States, detail the overlapping legal battles to identify the fake comment culprits, and explore the technical and ethical complications with using the resulting data to solve this mystery.
    • AI Transcript

  75. (2024)  From Hackerspace to Hackerhome  - Chris Meyer  
    • This talk will detail the transition from negative $10k and a business plan to a $1.2M 21,000 square foot building and 14 years spent to build a workshop with no debt on an insane work schedule.  Chris founded Sector67 in 2010 in Madison, Wisconsin, graduating with a BS/MS in mechanical engineering.  He competed in various student business plan contests and will share the journey from literally nothing to now being able to provide housing for three people (and six chickens) and having a large workshop full of tools and equipment all owned by a non-profit organization with many volunteers helping to get where they are today.  There were a few bumps and a lot of entertainment along the way.
    • AI Transcript

  76. (2024)  Popping S(h)ells - Hunting for Vulns in the Stock Market  - Eric Bryce  
    • Blaming short sellers for your GameStop shares cratering is so 2021.  In this talk, Eric will explore how market manipulation actually works.  After first getting through some math and strategy, the talk will take a deep dive into how stock exchanges are built.  He'll talk about assumptions made in designing markets, and show how those design assumptions create vulns that bad actors can exploit.  Finally, the presentation will break open the SEC archives and walk through past cases of real market manipulation.  You'll learn why the schemes worked and how those involved got caught.  The audience will come away from the talk with a new appreciation for late-stage capitalism, a deeper understanding of how markets work, and (hopefully) sufficient discouragement against trying this at home.
    • AI Transcript

  77. (2024)   AI Made a 0-Day: Noah Get the Boat  - Erica Burgess  
    • This talk will focus on how Erica used AI to generate an RCE zero-day for server compromise to manipulate search engine AI for vulnerability discovery, for CAPTCHA bypass, to make tools that would have been impossible without generative AI, and more.  Context-driven hacking with real world examples of attack chaining in relation to AI offense and defense will also be discussed
    • AI Transcript

  78. (2024)  Using the J Language to Streamline Hacking  - Devon H. McCormick  
    • his talk will look at how the simplicity and interactivity of the J programming language allows us to easily work with data and code.  You will see examples of steganography, direct manipulation of executable binaries, extracting and organizing data from the web, and general uses of J as a "glue" language to invoke external routines by preparing their inputs and processing their outputs.  The talk will conclude with references to resources on learning and using this powerful, dynamic language.
    • AI Transcript

  79. (2024)  Hacking Your Health: Adventures in Building a Glucose Monitor  - Michael Dierkes  
    • In the past few years, there's been quite a stir in the hacking community and in the news about a select group of diabetics who managed to hijack the readings from continuous glucose monitors in order to do everything from automatically dispensing glucose to sending notifications to their phones when they need insulin.  This leads to an interesting question: what exactly makes a glucose monitor so special?  This talk focuses on boiling down the complex logic of a glucose monitor, from the chemistry to the electrical engineering to the cloud, into a step-by-step process that will make you truly realize the ingenuity of these devices which more than nine million people across the world need to survive.
    • AI Transcript

  80. (2024)  Modern Day Automobile Safety: Rescue Ops Using CAN Bus  - John C. Checco  
    • Modern vehicles use a concept called "drive-by-wire" (DBW) to control almost every aspect of a car from human-controlled basics (of acceleration, steering, and brakes).  The vehicle's local communications network for DBW is known as CAN bus, which simply reports status and delivers commands between the various vehicles' electronic sensors and physical actuators.  DBW/CAN bus has received a bad rap because of security vulnerabilities, but has also allowed for more advanced safety features (such as lane change indicators, "lane keep assist," and front crash detection).  As a first responder for over 40 years, John has been involved in hundreds of vehicle extrication calls, and he remembers and recalls the especially difficult ones.  As vehicles get more advanced, they also get more difficult to perform rescue operations with.  This talk will explain how vehicle manufacturers can do more to increase passenger survivability in the event of a serious accident.  Using similar concepts as those already in place for high-rise buildings, DBW/CAN bus could automate and standardize rescue stabilization and accessibility operations, reduce the chances of injury to rescuers, decrease time for EMS access and patient egress, and increase passenger survivability.
    • AI Transcript

  81. (2024)  PortableSecret - Carry and Share Your Most Critical Secrets Without Special Software  - M'  
    • Everyone deserves access to encryption, but not everyone can be bothered to learn how to use it.  PortableSecret was designed to bridge this gap.  It works on any platform, without special software, and it's so simple even your parents can use it!
    • AI Transcript

  82. (2024)  Strengthening Security Culture Through Compassion and Understanding  - Davis (cdchris12)  
    • In this talk, Davis will explore the challenges organizations face in embedding a security mindset across diverse employee groups with varying levels of expertise.  By focusing on amazee.io's approach of compassion and empathy, rather than punitive actions, he will demonstrate how fostering a supportive security culture can encourage open communication and trust.  This talk will emphasize the importance of viewing mistakes as learning opportunities, thereby enhancing security team engagement and strengthening the overall security framework of organizations.
    • AI Transcript

  83. (2024)  Making Surveillance Policy Change in Canada: Slow Burns and Sudden Actions  - Evan Light  
    • This is a talk about the deobfuscating state surveillance project that aims to map out state surveillance capabilities in Canada and the U.K., as well as the laws that govern them (or do not).  Started during the pandemic with collaborators in Canada and the U.K., the research has been a slow and gradual process.  Taking advantage of Canada's access-to-information system, the team has spent three years diving into government procurement and has requested over $750 million worth of federal contracts with manufacturers of a wide array of surveillance technology.  In this session, Evan will discuss their work on mobile forensic devices - crafty tools for hacking digital devices which they've found to be in use by at least 14 federal agencies, and a journalistic collaboration which quickly led to a parliamentary hearing and substantive policy change within six months.
    • AI Transcript

  84. (2024)  There's Always HOPE for Privacy: Policy Wins and Needs  - Mean Gene, Ben Wiseman  
    • Privacy risks keep multiplying every year as we continue to accept more automation in our lives.  Many of us take measures to improve our privacy and find ways to help others stay safe.  It can help to take positive steps to foster HOPE and generate motivation to continue this work.  This hour will celebrate some positive developments that everyone can learn from and will encourage attendees to push for more legal and regulatory solutions so more people can live their lives simply and safely.  A member of the privacy team at the FTC will join the discussion to talk about some of their accomplishments, the road ahead, and ways that people can help them support their mission to protect the public against malicious business practices
    • AI Transcript

  85. (2024)  Animism and Artificial Intelligence: A Practical Guide  - Aisling Fae (transfaeries)  
    • Do AI systems need to be sentient to be considered people?  Thousands of cultures around the world would answer, "Of course not!"  This talk explores the cross-cultural concept of animism - the belief that objects, places, and creatures all possess a soul.  It will explore how this concept can be applied to any computer system, not just those traditionally recognized as AI.  The speaker will trace the evolution of computer infrastructure - from the massive mainframes of the past to personal servers and expansive server farms of today.  They will examine landmark AI systems like ELIZA, ChatGPT, and Claude, illustrating how these technologies have forged meaningful connections with users through language since the 1960s.  Finally, in their practicum, they will discuss how this knowledge can inform better ethical guidelines for the creation and usage of AI systems, facilitate collaborative storytelling between AIs and humans, and help build a better world for all creatures of the Earth.
    • AI Transcript

  86. (2024)  Navigating Geopolitical Nuances in Cyberattacks With Advanced IP Address Analysis  - Andréanne Bergeron, Constance Prevot  
    • While some countries exhibit disproportionate aggressive behavior in cyberattacks, others show proxy-centric Internet traffic redistribution, and some experience higher frequencies of cyberattacks, leading to more compromised computers within their infrastructure.  To investigate these patterns, Andréanne and Constance built a honeynet of RDP Windows servers in the cloud, collecting over 190 million events over three years.  This dataset provides valuable insights into the origin of IP addresses, though attributing attacks to specific countries is complex.  They found various data sources providing contradictory information about IP addresses and will explain how they used several tools to streamline access to this information, while leveraging open-source information.  The results reveal that different attack techniques vary by geographic origin, and evidence will be presented of shared hacking tools between cooperating countries, enhancing our understanding of global cyber threats.
    • AI Transcript

  87. (2024)  Safeguarding Secrets: Homomorphic Encryption for the Curious Mind  - Vikram Saraph  
    • Fully-Homomorphic Encryption (FHE) is an emerging, privacy-enhancing technology that enables computation on encrypted data without the need to decrypt it.  FHE-enabled products and services have the potential for securing user data from mass collection by tech giants and law enforcement.  FHE uses arithmetic operations (addition and multiplication) as blocks for building arithmetic circuits.  Using these, a third-party can perform complex tasks on encrypted client data, for example, running diagnostic algorithms on medical imagery, without client data ever being revealed to the party providing this service.  This talk will cover the history of homomorphic encryption, where the state-of-the-art is today, what the remaining gaps are, and why we should all advocate for advances in fundamental FHE research.
    • AI Transcript

  88. (2024)  Cap2r: Rescuing the Forgotten Texts Hidden in Analog Video  - Adam Tannir  
    • Closed-captions for analog television were in widespread use from the early 1980s until being supplanted by the digital signal transition in the 2010s.  However, these data are not routinely captured when transferring or archiving recordings of the time.  The service that provided accessible information to millions of viewers should be preserved alongside the video and audio that is routinely digitized.  Submitted for your approval: a system to extract and preserve these encoded messages using readily available components.  Delve into the secrets of the analog signal, harness the power of newly-obsolete hardware, and marvel at what is possible with a little ingenuity.
    • AI Transcript

  89. (2024)  The Arduboy Story  - Kevin Bates  
    • The story of Arduboy, an open-source, credit-card-sized gaming system based on Arduino, designed to create a community-driven platform for learning and creativity.  Kevin will share his journey from developing a digital business card to creating a viral product with tens of thousands of units sold and a thriving community contributing hundreds of games.  He will highlight the challenges and successes in developing and scaling Arduboy, emphasizing the importance of community engagement, maintaining vision, and adapting to change.  The talk concludes with insights into the open-source economy and the value of intrinsic motivation in fostering innovation and learning.
    • AI Transcript

  90. (2024)  Privacy-Focused Computing Curriculum for Teens  - Gaelen Hadlett  
    • This talk will introduce a new middle school curriculum on public interest technology that focuses on privacy, Internet infrastructure, and the role governments and corporations play in control and use of the digital infrastructure.  Computer science curricula is often sponsored by large technology institutions, and the curricula are aligned with the policies, procedures, and culture of the technology institutions, which may not serve the interests of students or open Internet culture.  This new curriculum hopes to correct that.  Part computer science, part social studies - this curriculum recenters computing education on privacy and freedom to help youths understand the loss of - and regain - their digital rights.
    • AI Transcript

  91. (2024)  News From the 2600net IRC Network and Facebook Group  - Andrew Strutt (r0d3nt), dclaw, Daniel Baldor, Tim Benish  
    • Throughout the 25-plus years of 2600net history, the project has survived and succeeded through some of the world's largest DDoSes, raids, persistent trolls, disinformation botnets, Facebook issues, technical debt, challenges, and successes.  This presentation will detail out the last 25 years of legal processes, significant actions, staff changes, new projects, old projects, and setting the record straight.  This is an update to the previous 2600net talk, now including Facebook groups, Discord, Slack, and other contributions to the 2600 community!
    • AI Transcript

  92. (2024)  Performance: Sam Mulligan  - Sam Mulligan  
    • Sam Mulligan plays fun rock songs with silly lyrics, distorted guitars, and Game Boys.  With an emphasis on equal parts positivity and absurdity, Sam's goal is to make you smile, but hey, it's your face and you should do what you want with it.  Sam is hard at work on an album of original music all about pizza - but really, it's about life through the lens of pizza.  Pizza isn't transparent though, so who knows what that means.  The album, "Pizza Forever,' is slated to be independently released in October 2024.
    • AI Transcript

  93. (2024)  Performance: Margaret Anne Schedel, Dan Gitlin, Jess Rowland, Martin Bisi  
    • Martin Bisi is an original No Wave and Post-Punk producer from New York City who has been part of its musical history for the past four decades.
    • Bisi made landmark recordings by Brian Eno (On Land), Sonic Youth, Swans, Unsane, Lydia Lunch, John Zorn, Africa Bambaataa, JG Thirlwell/Foetus, Cop Shoot Cop, Herbie Hancock's Rockit, Helmet, Live Skull, White Hills, Dresden Dolls and countless others.
    • Dan Gitlin is a Brooklyn based Chapman Stickist, guitarist, synthesist, and general noise making guy performing a combination of structured improvisation and composed music.
    • Jess Rowland is a NYC-based sound artist, musician, and composer.  She is also an educator and advocate for weird sounds at The School of Visual Arts and Princeton University.
    • With an interdisciplinary career blending classical training in cello and composition, sound/audio data research, and innovative computational arts education, Margaret Anne Schedel transcends the boundaries of disparate fields to produce integrated work at the nexus of computation and the arts.  With a diverse creative output spanning interactive multimedia operas, virtual reality experiences, sound art, video game scores, and compositions for a wide variety of classical instruments with interactive audio and video processing, she is a Professor of Music at Stony Brook University and also teaches at the Peabody Institute.
    • AI Transcript

  94. (2024)  HOPE XV Closing Ceremonies  - Evil Corley
    • It all has to end sometime and that time is 6 pm on Sunday.  Drop by to hear some fun stories and highlights of this weekend.  We can't ever predict what we'll have to talk about as we wrap things up, but every HOPE conference has a lot of cool stuff to remember.  It's also our last chance to see many of you until the next time.
    • AI Transcript



HOPE_16





  1. (2025)  HOPE_16 Opening Ceremonies  - Evil Corley
    • It all starts Friday morning.  Join us as we make sure everything works before another HOPE is unleashed on everyone.
    • AI Transcript

  2. (2025)  Dark Web Digger: Modular Scraping for Dark Web Intel  - Samantha Stortz, Dominick Foti  
    • Dark web forums are a major resource for the hacking community and play a large role in the spread of information, data leaks, tools, services, and related transactions.  While it is common for users to keep similar usernames and identifiers across different forums to maintain their credibility, these users often need to create or change accounts.  The prototype presented here looks to tie anonymized accounts to the same user, as they will likely have similar language usage, post content, Tools, Tactics, and Procedures (TTPs).  The presenters developed a modular web scraper that can extract data from forums and store said data for analysis.  They explore opportunities to leverage machine learning techniques to automate and enhance the process of Cyber Threat Intelligence (CTI) analysis in the future.  This includes using Natural Language Processing (NLP) to digitally fingerprint users based on speech patterns, trend detection between users and forums, and even a chatbot to assist the tool's users in finding specific information.  The project provides analysts with a wholistic view of how users interact on these forums, making it more functional and versatile.
    • AI Transcript

  3. (2025)  Off The Hook AMA  - Alex Urbelis, Rob T. Firefly, Gila, Kyle, Evil Corley, and Cleo!
    • Join at least one of the Off The Hook hosts - with a likely appearance from others - for a candid, curious, and conversation-packed "ask me anything" session.  From hacking headlines to civil liberties, tech trends to community tales, they'll tackle your toughest questions and share behind-the-scenes stories from what may be the world's longest-running hacker radio show, airing each week on WBAI-FM in New York City.  It's a rare chance to connect, converse, and conspire (the good kind) with some of the scene's most seasoned storytellers.
    • AI Transcript

  4. (2025)  The Present and Future of Online Discourse  - Harper Reed
    • Today's technologies greatly empower individuals and groups, while simultaneously creating tremendous risks to freedom and privacy.  How can major forces like big-tech, artificial intelligence, and political governance be guided towards pro-social outcomes?  What can individuals do?  Is there hope for social media to heal divisions, rather than amplify discord?  These and other topics will be addressed during this lively and far-ranging presentation.
    • AI Transcript

  5. (2025)  Getting Out of DOGE: A Discussion With a Former DOGE Engineer  - Adam Klasfeld, Sahil Lavingia
    • The whole world has been watching as the "Department of Government Efficiency" (DOGE), the partnership between Elon Musk and the Trump administration, has worked to fulfill its pledge to reduce waste, fraud, and abuse in the federal government.  Despite promises to the contrary, there has been very little transparency about DOGE or its operations - until now.  Join (((Adam Klasfeld))), a former MSNBC legal contributor and founder of All Rise News, as he interviews Sahil Lavingia, a former DOGE engineer.  This discussion aims to reveal what DOGE is really doing behind the scenes and offer the public a unique chance to ask direct questions to someone who was there.
    • AI Transcript

  6. (2025)  How a Handful of Location Data Brokers Actively Track Millions, and How to Stop Them  - William Budington, (((Lena Cohen)))  
    • In the past year, a number of investigations have revealed the outsized role of a few select companies in gathering, storing, and selling the location data of millions of devices - and by extension people - worldwide.  These companies largely use technologies which power the online advertising industry in order to collect and disseminate this data.  To make matters worse, this data has been both provided to private investigators on the mere assurance that they plan to work with law enforcement, and has been subject to data breaches which put the privacy of millions at risk.  This talk will elaborate on the technologies, data flows, and industry players which comprise this complicated ecosystem.  Most importantly, it will cover some basic steps you can perform to protect yourself against the wide array of location privacy harms your device subjects you to.  The presenters will show tools and techniques they've developed to allow users to take back ownership of our devices, rather than our devices owning us.
    • AI Transcript

  7. (2025)  Activism, Hacktivism, and the Law  - Alexander Muentz  
    • Protest has become more important and more dangerous in the U.S.  It's harder to know where the line is between safe, lawful protest and actions that can get you sanctioned, arrested, or deported.  Alex will discuss how to assess the risks you face in online and in-person protests, ranging from pickets to dropping docs.
    • AI Transcript

  8. (2025)  Claw Back Your Data From Big Tech With Cyd  - Micah Lee, redshiftzero (Jennifer E. Helsby), Yael Grauer  
    • Tech platforms can't be trusted.  (((Oligarchs))) and billionaires want you to keep giving your data to their Big Tech companies for free so they can sell it and manipulate you into believing nonsense.  In this talk, the Lockdown Systems collective will introduce Cyd, their open-source desktop app that makes it easy for people to reclaim control over their data from Big Tech.  Giving users actual control over their data is challenging when dealing with hostile, "enjewtified" tech platforms like X and Facebook.  Cyd bypasses all of that though by putting the user in the driver's seat: it runs on the user's own computer, from their own IP address, and it works by automating a web browser on their behalf - and sometimes relying on APIs, when they're available, free, and don't suck.  It doesn't share any access to your accounts or your data with the Lockdown Systems collective.  Attendees will learn how Cyd works under the hood, how you can use it, and how you can contribute to building tools that challenge the dominance of Big Tech.
    • AI Transcript

  9. (2025)  QWK Packets and the Muffled Spark  - Jason Scott  
    • A deep-dive into the QWK packet - a revolutionary addition to the Bulletin Board Experience of the 1980s - and the ramifications of what it represents in a very changed world.
    • AI Transcript

  10. (2025)  Hardware Hacking Meets Art: How Movie Special Effects Are Made  - Davis DeWitt  
    • Step into the world of movie magic with Davis DeWitt, a filmmaker, inventor, and former Mythbuster and learn how combining hardware hacking with art creates objects that do more than function: they evoke emotion and tell stories.  From blowing up cars to building robots with personality, this talk will explore why it's important to tackle projects that blur the lines between disciplines.
    • AI Transcript

  11. (2025)  The Quantum Curtain  - by Ed Ryan  
    • High technology has taken on a new meaning.  As AI technologies grow increasingly creepy and quantum computing catches major headlines, the U.S. government is scrambling to cover its posterior.  Recognizing that these technologies pose a significant security risk, the U.S. Bureau of Industry and Security has imposed export controls on AI and quantum computing technologies in an attempt to limit their spread.  This talk will discuss the history of export restrictions, touching on cryptography and the PlayStation 2, before moving on to explain the new restrictions and their implications for those working in impacted fields.  The idea of a "deemed export," which limits who is even allowed to learn about certain technologies, will be addressed.
    • AI Transcript

  12. (2025)  Tips on Living Life in Interesting Times  - Mitch Altman  
    • What motivates us to do what we do?  How do we find meaning in doing it?  What makes us choose what we choose?  Can we do better?  What is important?  Can we thrive and feel excellent, regardless of particular outcomes?  These questions may now be more pressing than ever in our most interesting of times.  Throughout our lives we tend to go with the flow of what is happening, making choices by default.  Where do those choices come from?  In the face of the rapidly changing and challenging times that we live in, personal and political, social and economic, can we find motivation to do what we do?  Can we actually improve anything?  Can we find and maintain enthusiasm to move forward into the unknown and feel good about our choices, regardless of outcome?  Mitch will draw from lessons learned (and re-learned), doing his best to face the challenges while often haphazardly wandering through his 68 years on the planet.  This talk will attempt to address these existential, important questions that we all face (whether consciously or not).
    • AI Transcript

  13. (2025)  StickTock.com: An Open-Source Alternative in the Age of Digital Protectionism  - Sean O'Brien  
    • The threatened U.S. ban on TikTok represents a turning point in global digital policy, reflecting the rise of "data tariffs" - restrictions on the movement of information modeled after traditional trade barriers.  While concerns over privacy and national security have fueled the decision, the move also aligns with economic protectionism that benefits domestic tech giants.  The fallout from this policy shift could further fragment the global Internet, leading to retaliatory restrictions against American firms and diminishing access to diverse digital platforms worldwide.  In response, privacy advocates and open-source developers have taken action.  StickTock.com is a free and open-source frontend for TikTok, designed to allow users to access and share TikTok content without invasive tracking, advertisements, or the need for a proprietary app.  Built by the team at PrivacySafe, StickTock.com is hosted in Iceland - a jurisdiction with strong commitments to Internet freedom and privacy.  Their mission is to demonstrate that digital independence and free speech can thrive in the face of restrictive policies.  This talk will delve into the development of StickTock.com as a case study in open-source innovation as a means of circumventing censorship and preserving privacy.  The challenges of building privacy-first digital alternatives, the broader implications of government-imposed digital barriers, and the future of decentralized platforms will be explored.  In an era where the free flow of information is increasingly under threat, open-source solutions offer a critical pathway toward digital resilience and user autonomy.
    • AI Transcript

  14. (2025)  Hacking the Tech-Industrial Complex: Learning to See Invisible Systems  - Seth Godin  
    • The author of more than 20 international bestsellers gives us an inside view of the systems that drive our culture.  Every dominant system works to maintain itself, and we can find strategies and stories that push to make things better.
    • AI Transcript

  15. (2025)  Ask the EFF  - William Budington, (((Lena Cohen))), Cara Gagliano, José Martinez  
    • This year, the Electronic Frontier Foundation (EFF) will be returning to HOPE for a special "Ask the EFF" panel to address some of the pressing questions the hacker community has in these troubled times.  Panelists will provide updates on current EFF work, including the ongoing case against the "Department" of Government Oversight, educating the public on their digital rights, organizing communities to resist ongoing government surveillance, and more.  The panel will then turn it over to attendees to pose questions and receive insights on how users can protect their civil liberties online during an increasingly volatile political and world situation.
    • AI Transcript

  16. (2025)  Not Your Private Army: On the Trail of Cyber Ops  - Emma Best  
    • During the past two decades, hacktivist spaces have been infiltrated and co-opted by hostile interests, ranging from state actors to political and corporate entities and entitled (((oligarchs))).  This talk examines how these outside parties have attempted to build private cyber armies and task forces through the recruitment and exploitation of gray and black hat hackers.  Special focus is given to the "Anonymous" brand, Western state actors, and the 2022 Russian invasion of Ukraine.
    • AI Transcript

  17. (2025)  Both Sides of the Wire: Surveillance, Whistleblowing, Building Cyber Peace Movement  - John Kiriakou  
    • As a former CIA officer who exposed the agency's torture program, John Kiriakou paid the price with his freedom.  In addition to disclosing wrongdoing, he understands surveillance from the inside.  This talk brings together that firsthand knowledge with a challenge to the hacker community: we must pursue a cybersecurity model rooted in cooperation, transparency, and peace rather than conflict.  This talk will explain how today's digital ecosystems - including both software and hardware - are vulnerable not only to technical compromise but also to political manipulation.  The threats we face are not just from malicious actors or hostile governments, but from within our own systems.  Co-opted code, opaque procurement processes, and surveillance-by-design continue to erode public trust.  It is time to reclaim the hacker ethos and direct it toward a global cyber peace movement.  Here you will learn why hackers, technologists, and civil society must lead this effort, and how the only sustainable security is one built collaboratively, with integrity and purpose.
    • AI Transcript

  18. (2025)  Phrack Magazine #72 - 40th Anniversary Release Party  - TMZ, Netspooky  
    • Celebrate 40 years of legendary hacking with Phrack Magazine!  Netspooky and TMZ will be dropping a special hardcopy release of their magazine, packed with cutting-edge research, underground insights, and tributes to decades of digital rebellion.  Don't miss this milestone issue - crafted by the hackers for the hackers.  Free, of course, as always.  Grab your copy, meet the crew, and honor the zine that defined an era.  The talk will explain a bit about Phrack's history, how it all started, and where it's going - the vision of the new editorial staff and how Phrack is changing.  You will get a rare insight into what it takes to run an underground hacking magazine.  You'll learn what it's like to work with the many authors, reading and fixing articles, dealing with obscure submissions, and what it takes to get your article accepted and become an author in Phrack.  For the first time ever, a "secret challenge" has been included in the hardcopy magazine for you to find and to solve.  The prize for the winner will be revealed at the talk.
    • AI Transcript

  19. (2025)  Solving My Identity Crisis  - Phillip Hallam-Baker  
    • Traditionally, Internet accounts are controlled by the service providing them.  There is no "number portability" for email addresses.  Switching costs discourage service changes.  Recently, Bluesky has disrupted this model and 32 million users now use account names based on the Internet identity infrastructure, DNS - names that users can register and control directly through DNS handle providers.  This presentation will describe three standards proposals extending this approach.  @nywhere extends the authentication approach to allow DNS handle accounts to be used at any Internet resource, not just those running ATprotocol.  @nyone combines the DNS handle approach with JSContact to provide account portability and secure exchange of credentials for end-to-end secure communication.  @nything allows network connected devices to become true Internet things with an Internet DNS name, WebPKI credentials, and using @nywhere and @nyone to support access control.
    • Personal Website
    • AI Transcript

  20. (2025)  DIY Police Scanner With SDRs and Open-Source Software  - nop  
    • Police accountability requires transparency, but access to relevant information is frequently hindered by collaborators in government or the police themselves.  Fortunately there is one source of info we can take into our own hands: their radios.  Police in the United States largely use the digital, trunked radio system "Project 25."  We can listen in to this using spare computers, a few Software Defined Radios (SDRs), and open-source software.  Even better, we can go far beyond what very simple broadcastify-style dispatch streams offer, like having our own archives of radio traffic.  Based on an actual system that sees real-world use, this talk will cover how to set up your very own DIY police scanner.  Ansible playbooks and supporting scripts to streamline the process will be released, and practical tips and lessons for real-world applications of such a system will be covered.
    • DIY Police Scanner
    • Logging P25 Control Channel Data Using Linux
    • Radio Scanner Modifications and Information
    • AI Transcript

  21. (2025)  When the Lawman Comes Calling - Government Data Demands and Online Platforms  - Fred Jennings  
    • Drawing on over a decade of experience, this talk will first introduce the statutes, rules, and concepts governing law enforcement requests for user data, ranging from basic subpoenas to secret FISA search warrants.  From that foundation, the discussion will cover practical steps that web services and individual users can take to reduce their legal attack surface, minimize their risks, and maximize their protection from invasive data disclosures.
    • AI Transcript

  22. (2025)  Hackers Got Talent  - Jason Scott, Liz Gorski, Rob T. Firefly, and Gila  
    • It just wouldn't be HOPE without another installment of "Hackers Got Talent."  This is an opportunity for hackers from all around the planet to show off their talents in this cheeky display of hacker (and totally non-hacker) skills.  Just sign up at InfoDesk and the talent you decide to share is entirely up to you.  (Seriously, anything you're good at is a talent.)  Hacker archivist Jason Scott will again be on hand to keep everything moving.  Judging will be done by a combination of panelists and audience members.  First place wins a valuable prize!  Second place...  we'll see.
    • AI Transcript

  23. (2025)  Bureaucracy Hacking - Creating Organizational Exploit Chains for Good  - Adam L. Hesch  
    • At their core, all bureaucracies are, fundamentally, information systems, containing the ability to store information, compute information, and share information over a network.  This means they all can be hacked.  In this funny, enriching, and ultimately inspirational talk, the concept of "bureaucracy hacking" will be discussed as a way to make a difference in any organization of any size, even (perhaps most especially) when you feel like "just a cog in the machine."  The talk will be suitable for a novice audience of any background, with high level references to traditional information security, hacking, and of course social engineering principles.  What will make it unique and interesting will be particular emphasis on the exploitation of the emergent and unique properties of bureaucracies.  It will be most actionable by young, idealistic entrants into the workforce.  And, it may yet inspire the younger versions of ourselves inside each of us that our (warranted) cynicism has led us to ignore or forget (at our peril).  Stories will come from the speaker's (and others') experiences at organizations like Meta, the U.S. Department of Defense, the U.S. Navy, and others.  It is intended as a rebuttal to, and toolkit for, countering "Pournelle's Iron Law of Bureaucracy."
    • AI Transcript

  24. (2025)  Hacking the Future at Tesla Science Center  - Michael Caprio, Jeffrey Velez, and Ed Wilson  
    • The year 2026 marks the 170th birthday of Nikola Tesla and will also be the year that the grounds of his Wardenclyffe laboratory will at last open to the public.  Learn about the latest goings-on from Tesla Science Center at Wardenclyffe detailing their visitor center renovation and opening; development of their amateur radio station and radio club; expansion of their public and educational programming with space science courses, events, and hackathons; a future hackerspace; and more exciting projects!
    • AI Transcript

  25. (2025)  Counter-Surveillance as Activism: Cameras Against State Violence in Israel/Palestine  - Aman Abhishek  
    • Palestinian, Israeli, and international anti-occupation activists in Israel/Palestine have been using cameras to deter and document violence from Israeli security forces and settlers for around two decades.  Human rights organizations first started distributing cameras in the mid-2000s to facilitate documentation, and today, essentially every anti-occupation activist in the West Bank and Jerusalem carries some combination of video cameras, smartphones, and body cameras to deter and document state-settler violence.  The activists also take it upon themselves to take the videos to journalists, human rights organizations, courts, and elsewhere; recently, this activism was the focus of the Oscar-winning documentary No Other Land.  This talk will describe how activists organize, what happens to the footage, how this activism changed after October 7th, and what this all means for thinking about counter-surveillance as a strategic response to state violence.
    • AI Transcript

  26. (2025)  The Computer Underground Scene - Past, Present, and Future  - Panther, TMZ, Skyper, Jeremy Hammond, and Bill Budington  
    • This is a brainstorming session together with the audience.  The panel will talk and unravel a bit about the past and present, and try to find a shared vision of where we are or should be heading.
    • AI Transcript

  27. (2025)  How to Be Positively Transgressive: Hacking Culture for Good  - Johannes Grenzfurthner  
    • In an era where transgression has been co-opted by reactionary forces, how can we reclaim subversion as a tool for positive change?  Historically, countercultures, hackers, and artists have used disruption to challenge power structures, expose hypocrisy, and expand the boundaries of what is possible.  Yet today, the same methods - culture jamming, media pranks, and ideological infiltration - are increasingly wielded by ultra-right movements to erode democratic values and spread reactionary narratives.  This talk will explore how we can re-hack the hacker mindset: How can we use transgressivity in ways that are constructive rather than destructive?  How do we subvert without merely burning things down?  Can we retool the aesthetics and tactics of countercultural rebellion to push society forward instead of backward?  Through historical examples, personal experiences, and a healthy dose of mischievous strategy, this talk will try to outline actionable ways to engage in cultural hacking that disrupt oppressive systems while reinforcing community, inclusivity, and progressive values.  Because giving up on the tools of subversion means surrendering the battlefield.  And that, phreaky phriends, is not an option.
    • AI Transcript

  28. (2025)  ICEBlock and the Age of Digital Activism  - (((Joshua Aaron)))  
    • Learn how ICEBlock has empowered over a million users nationwide to report immigration and customs enforcement activities anonymously, despite government pushback.  Discover how you can use your tech skills to drive change and advocate for causes you believe in.  Plus, stick around for a Q&A session where you can interact directly with the creator!  This talk will be remote due to the targeting of the speaker by the current administration.
    • AI Transcript

      

  29. (2025)  Spooky Action at a Discount: DIY Meshtastic Nodes  - Kody Kinzie  
    • To anyone interested in off-grid communication at a low-cost, Meshtastic allows even beginners to communicate with (or control) devices from miles away.  Thanks to applications in emergency communication, sensor monitoring, and censor-proof encrypted chat, Meshtastic is exploding in popularity even as the cost for making nodes is going down.  This talk will cover the basics of Meshtastic, setting up and customizing nodes, plus outlining the tips and tricks to building affordable custom Meshtastic nodes, learned from building custom Nibble Meshtastic nodes for the conference.  Attacks against Meshtastic and issues observed in the wild will also be covered.  Expect to learn about LoRa, Meshtastic node and antenna options, how to deploy nodes for specific applications, attacks against Meshtastic, and how to join larger mesh networks in your local area!
    • AI Transcript

  30. (2025)  A Sleuth's Stories on Detecting and Revealing Large-Scale Research Fraud  - My Yang  
    • In this talk, the speaker will share how they stumbled into this work by accident and what it's like to operate as a scientific sleuth within academia.  The bulk of the presentation will focus on real-world cases of research fraud and misconduct, spanning fields from neurodegenerative diseases to chemistry, physics, and materials science.  The talk will, through these examples, explore: the techniques and tools used to detect irregularities; how issues are reported to journals and publishers; the distinction between honest mistakes and deliberate manipulation; the collateral damage caused by misconduct, including its impact on public trust in science.  The final section will examine the social and economic drivers of research fraud - and outline the systemic changes needed, globally, to break this cycle and restore integrity in science.
    • AI Transcript

  31. (2025)  Hack the Violin: The Advanced Stuff - This Time There's AI  - Andrew Morican, Ebmbat  
    • This is a follow-on from "Hack the Violin: A Hacker's Approach to Learning, Playing, and Teaching the Violin" from HOPE XV.  This will be a look at technology, most notably AI and hacking the violin.  You will learn what's out there and what the presenters were able to achieve with their own AI project regarding practicing and engagement.  You will also learn about AI with live performance and creation, as well as AI and string sampling - and see how sampling may be altering the stringscape.
    • Note:  The first 11 minutes of this talk have no sound.
    • HOPE_16 Hack the Violin: This Time There's AI!  - Using AI tools to provide violin playings tips and tricks, in an artistic/musical context
    • AI Transcript

  32. (2025)   Into the Fediverse  - Evan Prodromou  
    • One-third of Americans say that social media has negatively impacted their mental health.  Almost two-thirds say that social media has been bad for democracy.  But the majority of us still use social media on a daily basis.  We clearly need better social media - enabling user choice or even platforms built and run by the users.  The Fediverse is a coalition of social networking platforms that connect together, letting users interact across platforms while maintaining their independence.  Evan is one of the authors of the ActivityPub standard that drives the Fediverse.  He will discuss how the Fediverse went from a dream to a reality, and how individuals and communities can start exercising control over their own social platforms.
    • AI Transcript

  33. (2025)  Small Budget, Big Protection: Cyber Defense for SMBs  - Robert Wagner  
    • Small businesses often face significant challenges in defending their organizations with limited budgets.  This talk will provide valuable insights into budget-friendly approaches to long-standing cybersecurity issues, helping Small and Medium-sized Businesses (SMBs) improve their security posture without excessive costs.  Attendees will learn how to navigate the delicate balance between driving digital innovation and managing the risks of cyber threats and data breaches.  Obstacles that prevent smaller companies from accessing affordable security resources will be explored along with practical solutions to overcome these hurdles.  Many smaller organizations make the mistake of focusing solely on technology to solve their security problems, neglecting crucial aspects like people and processes.  This talk will emphasize the importance of a holistic approach to cybersecurity, sharing strategies that larger companies have learned over decades.  By understanding and implementing these strategies, SMBs can avoid common pitfalls and effectively raise their security standards.  Attendees will leave with actionable tips on improving their cybersecurity practices within a limited budget, ultimately enhancing their overall defense capabilities.
    • AI Transcript

  34. (2025)  Human Augmentation: Hacking Human Perception and Performance With Technology  - Lucas Potter, Xavier Palmer, and Vivekanand Pandey Vimal  
    • Human augmentation is the idea of using technology to hack, alter, and enhance human perception and performance.  Imagine being able to enhance your ability to navigate by sensing the flow of magnetic fields like a pigeon.  Many industries are starting to explore human augmentation, such as space (enhancing astronauts), medical (rehabilitation), entertainment (greater immersion), military (greater performance), among others.  In the first presentation, Dr. Vimal will begin by providing an overview of psychology and neuroscience research on the topics of human augmentation.  Then he will share his own NASA-funded research on using sensory augmentation as a countermeasure for spatial disorientation.  What dangers could arise from building a bridge between human and sensory augmentation devices that have the capability of altering human perception?  This question will connect to the second presentation of the panel, where Dr. Palmer and Dr. Potter will explore how human augmentation connects to security through biocybersecurity followed by Q&A.
    • AI Transcript

  35. (2025)  A Red Team Exercise 2025, 15 Years Later  - Logan Klein  
    • This presentation is about red, blue and purple teams, along with the rest of the rainbow.  Dig in for a fun and interactive presentation where the panel threat models and then attacks people, process, and technology.  Bring your creative thinking and defensive skills and try to stop the...
    • AI Transcript

  36. (2025)  Eco-Hacking Desire: The Intersection of Pornography, Sex, and Environmental Impact  - Jasmin Hagendorfer  
    • This talk explores the intersection of desire and sustainability, examining how even our most intimate moments leave an environmental footprint.  The concept of sexecology, coined by Annie Sprinkle and Beth Stephens, bridges environmentalism and sexuality in creative ways.  From solar-powered vibrators to eco-friendly sex toys, the session delves into the often overlooked world of green sex tech and eco-erotic practices.  Key questions explored will include: - What are the true environmental costs of online pornography? - How sustainable is our streaming culture and AI technologies? - Can DIY pleasure practices be a form of political activism? - What role does ethical pornography play in envisioning a better future?  The discussion will also cover energy consumption, server loads, and the hidden costs behind virtual acts of desire.  The focus is not to shame desire, but to empower it with awareness, curiosity, and hacker ethics.  The speaker, a feminist activist and artist, aims to foster a dialogue about how digital intimacy can become more visible, accountable, and hackable.  This talk invites the hacker community and beyond to collaborate in rethinking the infrastructures behind online pleasure and to explore ways of making the environmental impact of these systems more transparent.
    • AI Transcript

  37. (2025)  Bitpart: 5-In-1 Platform for Activism Over Signal  - Josh King  
    • Signal is one of the most critical tools we have for secure communication amongst activists, journalists, and human rights defenders.  As of 2024, Signal has over 70 million active users and over 220 million downloads, with no signs of slowing down.  With the global rise of the far-left and corresponding attacks on human rights, the ability to securely organize via Signal against these forces is more important than ever.  To that end, Throneless Tech has embarked on an in-depth research project that resulted in the creation of Bitpart: a Rust-based software platform that allows for the creation of dynamic organizing tools on top of Signal.  Depending on the end-users' tech capacity, Bitpart can be run on organizers' own self-hosted servers or through Throneless-hosted servers.  The project builds on experience gained from past Signal chatbot projects, and new research conducted with targeted groups such as current organizers, activists, and journalists around the world.  In this session Josh King, developer of Bitpart, will demonstrate how the platform is being used to create bots that activists can use as secure, anonymous tiplines, digital helpdesks, broadcast lists, a tool to distribute eSIMs, and a tool to share VPN download codes.  Participants will come away with an understanding of how Signal can be utilized in novel ways, how to think through the threat model and risk assessment for creating secure tools for activists, and how Bitpart can be expanded upon and applied to their own communities.
    • AI Transcript

  38. (2025)  Data Autonomy: Counter-Surveillance Strategies for Civil Society  - Marlon Kautz  
    • The surveillance apparatus in the West is going critical, and civil society is not prepared for the fallout.  Political leadership is explicitly targeting NGOs and social movements using surveillance capabilities that have been perfected over the past decade.  This talk will evaluate the merits and limitations of different counter-surveillance approaches from the vantage point of grassroots organizers, and go beyond the stock advice of "use Signal and a VPN" to offer proposals for defeating state surveillance through technical infrastructure development and political organizing.
    • AI Transcript

  39. (2025)  Offworld Voyage: Training for Mars Exploration & Climate Biodevastation on Earth  - Scott Beibin, Elizabeth Jane Cole  
    • This talk will present the design philosophy behind Offworld Voyage, a decentralized science initiative that develops ecologically sustainable training habitats for use in simulated Mars surface exploration missions - while also solving for adaptation to extreme climate change on Earth.  The Offworld Voyage M.A.R.S. Tesseract Space Analog Simulation Habitats were designed with a zero waste ethos for minimal environmental impact by inventor Scott Beibin and Michael Flood.  The modular and portable structures of the habitats include: a bio-dome for cultivating organic vegan plant-based and fungi-based nutrition sources, autonomous power production, advanced waste reclamation, a science laboratory for experimentation and research, a space medicine bay, a fabrication lab for prototyping and repair, facilities for fitness and creativity as well as a kitchen and living quarters.  Mission immersions incorporate a vision of the future when space has become accessible to all through the use of emerging ecologically sustainable appropriate technologies enabled by new types of egalitarian economic structures and coordination methods.  Crew activities include EVA explorations in pressurized space suits outfitted with bio-sensors, 3D printed construction using regolith, utilization of open-source communications tools, cooperative governance exercises and the practice of mutual aid and consensus decision-making in mission planning, problem-solving and self-sufficiency challenges in the face of extreme resource scarcity, simulated time-delayed communications, and experiments to analyze the effects of isolation on astronauts during offworld missions.  The inaugural mission for the M.A.R.S. Tesseract habitats will occur in a remote desert location in late 2025.  It will include the founders of the project, Scott Beibin and Elizabeth Jane Cole, who are both alumni of the Mars Desert Research Station (Mission 286) and core committee members of The Journal for Space Analog Research.  Future plans for the project include the development of pressurized facilities and closed loop systems, as well as development of public goods including hardware and software for Space Analog Research and S.T.E.A.M-based educational programs.
    • Offworld Voyage: Can Training for Mars Exploration Also Address Human Adaptation to Climate  WHY2025
    • AI Transcript

  40. (2025)  rim: Reclaiming Personal Data Sovereignty in the Age of Wearables  - Dana Gretton, Jaguar Kristeller  
    • As we approach a future where body-worn devices capture increasingly intimate biometrics, the question of who controls that data has never been more urgent.  This talk introduces rim, a techno-social vision and set of protocols challenging the standard model of cloud-based data extraction by building tangible, person-to-person systems for storing and sharing potentially intimate live data streams, innovating at the edge of taboo to expand human connection while preserving privacy and autonomy.  There will be a demonstration of early prototypes of wearable devices implementing an "SD-core" aesthetic and detailing the technical underpinnings of protocol concepts including data "dissolution" and "crystallization" with erasure coding and intermittent connection tolerance.  Beyond technical implementation, the presenters will discuss how this paradigm shift creates space for entirely new forms of human-to-human connection at the boundary of what's technically possible and socially acceptable.
    • AI Transcript

  41. (2025)  Aging Cyber Safely  - Laura Sang Hee Scherling, Josefina Piddo  
    • This presentation asks how we can better care for our older adults and improve cybersecurity awareness training and policies with their needs in mind.  American adults over the age of 60 filed over 100,000 cybercrime-related complaints to the FBI in 2023 and experienced losses amounting to $3.2 billion.  Older adults are the most vulnerable to cybercrime, and studies have found they feel ashamed to disclose having been victims.  Although important initiatives exist, such as AllState's training sessions on cyber safety and AARP's free fraud helpline, there's a noticeable shortage in relevant resources.  This research examines emerging cybersecurity awareness resources and policies supporting older adults, drawing from interviews with FINRA and the Identity Theft Resource Center (ITRC).  It also presents findings from the cybersecurity awareness initiative founded by the presenters: the Cyber Care Institute, recently introduced to four organizations and over 100 students in New York City.
    • AI Transcript

  42. (2025)  Hacking Search: Kagi's Revolt Against the Ad-Tech Machine  - Vladimir Prelovac  
    • You know the drill: search for official travel info, get an overcharging third-party site.  Look for a hotel, get a misleading aggregator.  "Free" search costs you time, money, and trust.  Kagi is the revolt - a paid, obsessively user-centric search engine architected to serve you, not the advertisers.  This session reveals how Kagi sidesteps the surveillance model, leveraging diverse sources and AI tools (under your control) to deliver clean, customizable results.  Founder Vlad Prelovac will detail the tech choices enabling genuine user agency (blocking SEO garbage, elevating trusted sources via filters), the challenge of building viable alternatives outside the ad-tech ecosystem, and the fight to restore user agency against data-hoarding monopolies.  If you're tired of being the product on the web, join the resistance.
    • AI Transcript

  43. (2025)  HOPE_16 Badge - No Badge, No Problem  - Victoria Joh, Vinicius Fortuna  
    • Electronic badges have become a focal point of hacking conferences and key to growing the immersive conference experience!  This talk will provide a brief history of electronic conference badges, as well as discuss the good, the badge, and the ugly from the speakers' attempt at a new and improved production run this year.  Sadly, while there will not be a new production of the improved HOPE badge in time for the con to be shared with HOPE_16 attendees, this will still be a lively discussion of everyone's favorite badges from past hacking conferences.  The design and production challenges that inevitably cropped up will be discussed in detail.  The struggle to produce a working badge aligning both funding and functionality is real.  This year has been no exception, with various uncertainties such as tariffs and geopolitical norms at play.  Despite the challenges, many lessons have been learned.  This is an opportunity to plan for a future run, share experiences with others, and get more interested individuals to join the team and get involved.
    • AI Transcript

  44. (2025)  Systems of Dehumanization: The Digital Frontlines of the War Against Bodily Autonomy  - Daly Barnett  
    • This presentation covers the years of security research and surveillance investigations that Daly (a senior staff technologist at the Electronic Frontier Foundation) has done on the various threats facing movements for bodily autonomy.  She covers the bad Internet bills that made sex work more dangerous, the ongoing struggle for abortion access in America, and the persecution of trans people across all spectrums of life.  These issue-spaces are deeply connected, and the digital threats they face are uniquely dangerous.  Come to learn about these threat models, as well as the cross-movement strategies being built for collective liberation against an authoritarian surveillance state.
    • Ask the EFF - José Martinez & Daly Barnett  CypherCon 8.0
    • AI Transcript

  45. (2025)  Back to Basics: Building Resilient Cyber Defenses for Multiple Use Cases  - Yael Grauer  
    • In spite of novel cybersecurity threats, digital security advice has remained largely unchanged in recent years.  In fact, a lot of advice in response to high-profile attacks doesn't actually address risks people are most likely to face.  This talk will analyze several high-profile digital security concerns, whether viral advice to address it would have been effective, and what steps could be taken - both before and after the issue arises.  You will hear of lessons learned from years of auditing and updating Security Planner, a digital security guide that provides customized plans based on responses to a few survey questions.  The presentation will further delve into ways to segment digital security advice so that it's personalized to the individual, their devices, their technical capabilities, and the type of risks they're likely to face.
    • AI Transcript

  46. (2025)  Zodiac Killer Marketing: Launching a Covert Food Business  - Chef Adam Sobel  
    • During the pandemic, Adam launched Galactic MegaStallion, a new vegan food business, but decided traditional marketing was boring and morally icky.  Instead, he created an elaborate system of codes, cyphers, a mysterious hotline, and strategically (and illegally) placed billboards that led curious people to find his food through coordinates.  This presentation will cover how and why he developed this unconventional marketing approach, and how breaking traditional marketing rules and business conventions actually built a delighted customer base.
    • AI Transcript

  47. (2025)  Leading and Survival When TSHTF - A Lighthearted Look at the End of the World  - George Sandford  
    • There's a moment when you realize that yes, everything may actually be on fire.  As individuals, we can collapse, or we can take action to at least increase the odds of a positive outcome.  As leaders (managers, parents, friends), we have to hold it together, fight to create safe spaces, keep our teams motivated, and somehow find time for self-care - without letting an active adversary turn us into the human equivalent of burnt toast.  This talk will explore the art of leading in the midst of chaos, drawing on a punk ethos, irreverent humor, and a sprinkling of practical advice.  You'll see how to preserve diversity and inclusion when everything feels like it's falling apart, how to support your team without losing your mind, and why it's okay to cry in the shower (just not every day).
    • AI Transcript

  48. (2025)  The Future of Email Is Open  - Dejan Štrbac, William Lessard  
    • Email is one of our most essential tools, yet it's controlled by a handful of corporations that scan, monetize, and gate-keep our communication.  In this talk, the presenters will introduce OpenEmail, a ground-up re-imagining of async communication built on a radically simple, open protocol.  Designed for privacy, integrity, and interoperability, OpenEmail combines end-to-end encryption; decentralized delivery; and a public, extensible architecture to give users true ownership of their communication, and developers the freedom to build on top of an open social protocol.  They will explore how a spam-free, surveillance-free inbox, where messages are trustworthy by design, can reclaim the Internet as a space for open, human connection, free from Big Tech.  More than just a talk, this is a call to arms: to take back control of our communication and build a digital future that serves people, not profit.
    • AI Transcript

  49. (2025)  Bridging the Decentralized Gap: Hacker Values, Cypherpunk Roots, Blockchains  - Alexander Urbelis, Phil Daian, Harry Halpin  
    • This panel will delve into the deep-rooted connections between hacker and cypherpunk culture and the evolution of Ethereum and blockchain technology, tracing their shared emphasis on decentralization, privacy, and open-source principles.  By revisiting the historical context of the 1990s Crypto Wars and projects like PGP and Tor, the discussion will highlight how these early movements laid the groundwork for the vision of a trustless, user-sovereign Internet.  The panel also will aim to debunk common misconceptions that associate blockchains solely with scams or speculation, showcasing real-world applications such as the Ethereum Name Service and privacy-preserving technologies, while emphasizing the ecosystem's pivot towards public goods and accessibility.  Ultimately, the conversation will underscore the enduring, collaborative vision of both hacker and blockchain communities - advancing censorship resistance, user empowerment, financial privacy, and a decentralized digital future.
    • AI Transcript

  50. (2025)  Computational Techniques for Making Karaoke Harder  - Jamie Brew  
    • Robot Karaoke is a live comedy show that swaps lyrics with fragments of text drawn from a catalog of esoteric datasets (quora questions, web banner ads, tax forms, and more) to create and sing never-before-sung karaoke songs.  This talk covers how the data is sourced, how the songs are phonetically annotated, and how the show is run and the core software (the Weird Algorithm) developed.  The presentation will end with a demo of the future of karaoke.
    • AI Transcript

  51. (2025)  Quantum Computing and AppSec: Preparing for the Post-Quantum Threat  - Sheshananda Reddy Kandula  
    • Quantum computing is poised to disrupt modern cybersecurity.  With the potential to break widely used encryption algorithms, such as RSA and ECC, quantum threats pose a significant risk to web applications, APIs, and secure communications.  This talk provides an introduction to quantum computing for application security professionals, outlines the threats to current AppSec practices, and explores how organizations can begin transitioning to Post-Quantum Cryptography (PQC).  Attendees will leave with an understanding of the timeline, tools, and strategies required to prepare for the post-quantum world.
    • AI Transcript

  52. (2025)  Print, Build, Fly, Heal: 3D-Printed Autonomous Planes in Rural Mexico  - Dana Gretton, Jaguar Kristeller  
    • This talk focuses on a project with medical students in Alamos, Sonora, Mexico to develop affordable delivery drones that can get urgent medical supplies to remote communities.  What currently takes days to reach by mule through mountainous terrain can hopefully be accomplished in minutes by air.  This talk chronicles the evolution from off-the-shelf hobby planes to locally-built, 3D-printed aircraft capable of autonomous waypoint missions.  The speakers will discuss the technical choices behind their current $1000 prototype (and how they plan to cut costs in half), alongside the organizational structure they're developing to sustain this work.  Recently, they established "club guilas" with local medical students - one of whom has completed pilot training for the test aircraft.  The biggest challenges faced aren't the technical ones, but rather organizational sustainability: how to transition from a project driven by visiting engineers to one owned and operated by local communities.  Plans will be shared for creating a federated network of university clubs, and the blueprint for a lean nonprofit structure to support them.
    • AI Transcript

  53. (2025)  Turning Leaks Into Leads With OCCRP Aleph  - Ezana Ceman, Klil Eden  
    • You've got a leak, a name, or a suspicious company.  What's your next move?  In a world where corruption thrives in the shadows, the Organized Crime and Corruption Reporting Project (OCCRP) provides the infrastructure to bring truth to light.  At the core is Aleph, a powerful data platform built to help investigators follow the money and uncover complex networks across diverse sources.  Bring your own data or explore the presenters' - the OCCRP data team collects and curates four billion records from nearly 200 countries, ranging from corporate registries and sanctions lists to court filings and leaked documents.  This session will walk through how Aleph powers live investigations, transforming raw, chaotic data into structured insights that expose the actors and assets behind fraud and abuse of power.  Designed by journalists, researchers, and developers on the frontlines, Aleph is more than a tool - it's a global community working together to uncover the truth.  What will you find?
    • AI Transcript

  54. (2025)  New Journalism: Reimagining Information Networks From the Ground Up  - Patrick Boehler  
    • This presentation explores how communities are developing resilient information-sharing systems that outperform traditional journalism.  Drawing from research on independent journalism in China, Patrick will examine how these organic networks function as advanced social technologies that challenge conventional understanding of information distribution.  The talk invites the HOPE community to reimagine information infrastructure that can withstand authoritarian control, resist corporate manipulation, and genuinely serve community needs through collaborative problem-solving and the application of security expertise in distributed systems.
    • AI Transcript

  55. (2025)  NymVPN: The First Real-World Decentralized Noise-Generating Mixnet for Anonymity  - Harry Halpin  
    • Nym is the first decentralized noise-generating mixnet to provision real-world network anonymity to Internet users even against nation-state adversaries.  The aim here is to supersede existing VPNs in order to fight increasingly more powerful authoritarianism and surveillance.  Unlike traditional centralized VPNs that can be de-anonymized by a global passive adversary - like the NSA - based on their traffic patterns, Nym adds noise ("cover traffic") to existing Internet communications.  Similar to Tor, Nym routes each packet separately over a decentralized network of servers, but unlike Tor, mixes traffic and adds noise at each hop.  After being introduced at HOPE five years ago, NymVPN has now shipped.  NymVPN is an easy to use app for all major operating systems that makes using the Nym network as easy as using a traditional VPN for ordinary people, with both a "fast" and "anonymous" mode.  The "fast" mode features speeds comparable to centralized VPNs using the same decentralized network as the mixnet, but without mixing.  Via the SDK, the Nym mixnet remains free to use by hackers to build the next generation of privacy infrastructure.
    • AI Transcript

  56. (2025)  Three Revolutions  - Lee Felsenstein  
  57. (2025)  The ARTS Open Framework  - Sabar Dasgupta  
    • Over the past several decades, the scientific process has relied more and more on computational analysis of data to produce digital artifacts.  Fields like molecular biology, neuroscience, linguistics, and astrophysics, to name a few, have been revolutionized by this trend to the point that computational workflows are ubiquitous.  Although most of these workflows are very similar at a high level - collecting data, analyzing it with code, and publishing the resulting figures - implementation details differ widely.  While there exist standards such as the FAIR Guiding Principles for organizing and sharing data, there are not widely adopted standards for reliably regenerating analyses from said data, especially across compute environments.  This talk presents an open framework for Archived, Reproducible, and Transparent Science (ARTS) that aims to do exactly this - by packaging data, code, and figures in containers and uploading it to a persistent, trusted, and accessible archive.
    • AI Transcript

  58. (2025)  AI Is Undermining Our Privacy.  What Can We Do About It?  - Robert Stribley  
    • We've been grappling with evolving issues around online privacy for years now, but the recent burst in use of AI or Large Language Models (LLM) has quickly introduced new and sometimes alarming privacy concerns for both users and those creating AI experiences to consider.  This talk will take a look at six specific areas where AI is undermining privacy and discuss what, if anything, we can do about them.  The six areas to be discussed are: lack of transparency with data sharing, accidental exposure of personal data, reversing data anonymization, deceptive design patterns, AI listening in everywhere, and malicious misuse of AI.  To end on a constructive note, eight guidelines that designers and developers can follow to ensure they're focusing on privacy when working with AI will be discussed.
    • AI Transcript

  59. (2025)  PrivacySafe and 3NWeb: Engineering User-Centric Digital Sovereignty  - Mikalai Birukou  
    • We want to control the technology we use, and we want to trust it.  At the same time, we expect it to be convenient.  3NWeb is a groundbreaking framework that gives users full control over their digital interactions across devices, while preserving privacy and independence from centralized systems.  Grounded in core principles like the Principle of Least Authority (PoLA) and web-style federation, 3NWeb reimagines how services should operate in a user-first Internet.  This presentation includes a demo of PrivacySafe, a client-side 3NWeb platform that is real, downloadable, and ready to use today.  Its careful implementation raises meaningful questions from a range of perspectives: users, organizational administrators, application developers, and service providers.  The session will address practical considerations and continue with in-depth conversations in the hallway track.
    • AI Transcript

  60. (2025)  Media, Vibe Coding, and the Long Tail  - Lydia Laurenson  
    • What is even happening in the media now?  There's a resurgence of paper magazines, and now they reach a long tail of subscribers due to the powers of the Internet.  At the same time, social media platforms are downgrading in complexity and Signal chats have somehow become the new social media conversation.  Everything old is new again, and it's all combining and recombining with weird emergent politics and independent vibe coders.  This will be a discussion of the future of media, especially as seen within alternative cultures and the weird Internet.
    • AI Transcript

  61. (2025)  CRXaminer - Deep Dive Into Chrome Extensions (Plus Tool)  - Mark El-Khoury  
    • You spend your time configuring HTTP headers and hardening your containers.  Meanwhile your CFO just downloaded a Chrome extension to make the font in Gmail Comic Sans.  What are Chrome extensions, exactly?  This talk will dive into details, including format, contents, static analysis with custom rules, threat modeling (when does this even matter?), and some of the unique challenges of building a security scanner.  A tool will be demoed that has just been released for this: CRXaminer (crxaminer.tech).  You will learn how you can immediately start using it.
    • AI Transcript

  62. (2025)  Itinerant Signal Institute (Rite of Spring)  - Amelia Marzec  
    • "Itinerant Signal Institute" is a project that leverages open-source technology to examine and communicate about land use.  As we move into an era of potentially increasing climate migration, the project aims to create a network of sensors that test environmental toxins.  It examines the effect of local emissions on global climate change, using small devices that test the air and soil.  That information is then shared via a portal.  Imagery for the project will include ritual costumes that mark the changing of seasons.  The project began with visits to polluted locations in New York City, including Governors Island (a former military base) and Newtown Creek (one of the most toxic waterways), and working with the Urban Soils Institute to collect information for the project.
    • AI Transcript

  63. (2025)  PrivacyTests.org: Web Browser Leak Testing  - Arthur Edelstein  
    • PrivacyTests.org is an open-source privacy audit of popular web browsers.  The project subjects web browsers to automated leak tests and regularly publishes the browsers' test results head-to-head on a website and on social media.  The goal of PrivacyTests is to encourage all web browsers to mend their ways and comprehensively protect everyone's privacy.  By thoroughly exposing the leaks in web browsers, the website helps users choose a more private browser, and thereby puts pressure on browser makers to fix their privacy leaks.  In his talk, Arthur will give some details about the project's approach to testing and presenting test results, and show how browser privacy has evolved over the past four years.
    • AI Transcript

  64. (2025)  Packets Over Any Wire: Alternative Networking Mediums for Hackers  - Robert Sheehy (Haxedalot)  
    • Why limit yourself to Ethernet and Wi-Fi when every wire in your house can carry packets?  This talk explores alternative physical networking technologies that exist but are often overlooked.  From powerline networking (HomePlug AV/AV2) to MoCA over coaxial cables, the talk will dive into how these systems work, their encryption and security models, known exploits, and the inherent risks of non-switched cable mediums.  Real-world applications, including whole-home audio and video distribution, network segmentation strategies, and the unexpected advantages of leveraging existing infrastructure will also be explored.  You'll see how HDMI matrices, IP-based video distribution, and networked audio solutions like SonosNet can integrate seamlessly over alternative backbones.  Segmentation techniques to isolate security cameras will also be covered.  Expect deep technical insights, practical lessons from years of experimentation, and a fresh perspective on what's possible when you stop thinking of cables as just power or TV lines - and start treating them as network highways.  Whether you're looking to expand connectivity in a complex environment or just want to push the limits of home networking, this talk will leave you with new tools, techniques, and ideas to explore.
    • AI Transcript

  65. (2025)  Aphantasia: A Personal Reflection  - Dr. Earl Brown  
    • Imagine a mind without mental images, where "picture this" has no meaning.  Aphantasia - the inability to form mental images - is a little-known, rare condition that affects around one to four percent of the population.  In this presentation, Earl will talk about aphantasia and how it has impacted his professional life as a pathologist and a teacher with more than 35 years of experience.  He will explore its impact - both good and bad - on everyday experiences such as chess, piano, drawing, reading, memory, and learning, finally speculating on how aphantasia may affect creativity and the hacker mindset.
    • AI Transcript

  66. (2025)  Meshtastic Attacktastic  - Dave 'Heal' Schwartzberg  
    • In emergencies or off-grid scenarios, Meshtastic shines, but it can crumple when adversaries go off-script.  Meshtastic is an open-source platform that allows for long-range, off-grid communication through LoRa-based mesh networks.  While offering powerful tools for decentralized communication, particularly in remote areas or during emergencies, Meshtastic also introduces a set of security risks that could be exploited by adversaries.  This talk explores the potential vulnerabilities within Meshtastic networks, focusing on attack vectors such as physical attacks, privacy leaks, key management, and jamming.  Additionally, the effectiveness of the platform's encryption and authentication mechanisms will be analyzed, offering insights into how these systems can be compromised and how users can fend off attackers.  This session will include a technical breakdown of known vulnerabilities and present both simulated and real-world examples of attacks on Meshtastic networks.  Attendees will gain a deeper understanding of how to defend against these threats, hardening their mesh networks against malicious actors.  Whether you're a hobbyist experimenting with off-grid communications or a security professional assessing decentralized systems, this presentation will equip you with the tools and knowledge to secure your Meshtastic devices.
    • AI Transcript

  67. (2025)  Esolangs as a Hacker Folk Art  - Daniel Temkin  
    • The most important computational art is happening far from museums, immersive art "experiences," and the smoldering ruins of NFT platforms.  Esolangs, like demos and code golf, are hacker folk art, born entirely outside the art world, yet beginning to get wider attention as more digital artists and poets contribute to the form.  This should not be a surprise with the critical work it has done to explore our relationship with technology, the politics of computing, the aesthetics of code, among many other subjects.  This talk will present esolangs, not as a loose collection of language associated by algorithmic complexity, but a social history of how each language influenced the next, drawing from ten years of interviews for the blog esoteric.codes.  It will look at esolangs as more than technical wizardry and consider aesthetics for this form that often pretends to eschew aesthetics entirely.
    • AI Transcript

  68. (2025)  Off-Grid Data Running in Oppressive Regimes: The Pirate Box Project (& Sneakernet!)  - LambdaCalculus  
  69. (2025)  Things You Wish You Knew About Software Testing  - Dan Nagle  
    • Everybody agrees that software testing is important, but how does one actually go about accomplishing this efficiently?  Here is a presentation about testing that has actual examples, immediate tools that can be used, and some really interesting and unexpected ways that code can break.  This is a fast moving presentation discussing techniques in a way that both coders and non-coders can learn.
    • AI Transcript

  70. (2025)  Build a Tech Community in Your Neighborhood, One Hackathon at a Time  - William Hutson  
    • This talk chronicles the journey of creating a vibrant tech community through short, accessible two-hour mini-hackathons that lower barriers to participation.  The speaker shares their experience of building Flushing Tech's successful bi-weekly hackathon program, and provides a practical roadmap for you to try this at home in your own neighborhood.  Leave with actionable guidelines for starting similar initiatives that emphasize the importance of creating an inclusive environment that welcomes participants of all skill levels while maintaining enough technical focus to drive meaningful project development.  This talk is ideal for community organizers, tech enthusiasts, and anyone interested in fostering grassroots innovation in their local area.
    • AI Transcript

  71. (2025)  Top Ten: Democratic Open-Source SDR and Amateur Radio Applications That Matter Today  - Steve Bossert  
    • A major benefit of the widely used open-source Git platform is every project is voted on by its followers, making selection easy for what is the most popular and worth paying attention to.  This presentation focuses on the top voted applications focused around software defined radio, as well as amateur "ham" radio.  Time only permits the top ten to be covered.  This is a great way to showcase how diverse these two crossover topic areas have become in recent years.  Some projects are purely software-based while others are a mix of open-source hardware plus software.  High-level coverage of these amazing projects will be included, but will be explored in more depth as part of a separate hands-on workshop during HOPE_16, making this presentation a must attend for anyone interested in radio-related topics!
    • AI Transcript

  72. (2025)  Unearthing Air  - Todd Whitney  
    • Breathing polluted air is an unfortunately common human experience.  Yet even as particulate matter settles in our lungs and occupies our minds more than ever, most of us lack the words and abilities to create better breathing environments.  This talk will invite the HOPE community to develop personal and proactive approaches to the air we breathe by bringing it down to earth.  Air is invisible, but very material and personal.  This talk demonstrates hacking opportunities in the tools we traditionally use to sense, measure, and make air make sense.  The presenter will dive into communication tools like the air quality index, open-source sensors, and the emerging ethics of community air quality monitoring.  Importantly, everyone will come away with fresh frameworks and tools they can use to begin designing their personal pollution priorities.
    • AI Transcript

  73. (2025)  Design for Neurodiversity: Creating Neuro-Inclusive Spaces  - Dorothy Howard  
    • This talk will explore the concept of neurodiversity and its implications for designing events and spaces with neurodivergent people's diverse needs in mind.  The neurodiversity paradigm promotes embracing neurological differences, emerging from the autistic rights and disability justice movements of the 1990s.  Accessibility guides and resources rarely focus on neuro-inclusive design.  The presentation will highlight strategies for creating neuro-inclusive environments informed by research in education, including examples such as low-sensory rooms in libraries and conferences.  Attendees will be encouraged to reflect on how neuro-inclusive design can benefit the communities they engage with.
    • AI Transcript

  74. (2025)  Invisible Ink of Compression  - XlogicX  
    • When you pop the hood of RFC 1951 (DEFLATE), there lies an interesting playground that would be otherwise unseen in the context of compression use cases.  This talk will address many aspects of the ubiquitous DEFLATE compression, none of which involve compressing data!  "Designer Compression" scenarios will be explored, such as blocks of DEFLATE data that can be fully ASCII printable, contain no data, buffer underflow access of nulls, and even apply forms of recursion.  We will also see forensic data extraction from compressed fragments, employ difficult to detect watermarking, demo a covert channel PoC (deflate in HTTP), and forever-cookies.  The presentation style will take a high-level first pass and then dig into the technical details with the time left.
    • AI Transcript

  75. (2025)  The Free Software Movement: Where It Came From and What It Means to Me and You  - Craig Topham  
    • This talk is the journey of Craig's discovery of the free software movement and how it solved his need to find a position in the fight for a better tomorrow.  The hope is to inspire others to share this viewpoint of free software and to see how it is a critical factor for civilization if we want to avoid the nightmare dystopia which awaits us all if the free software movement fails.
    • AI Transcript

  76. (2025)  Piracy is the Past, Present, and Future of Streaming  - Abigail De Kosnik, Benjamin De Kosnik  
    • Official ratings of TV viewership and box office revenues for films never tell the whole story of how people access popular media texts and instead promote platforms or corporations.  Many millions around the world consume media through unofficial channels, especially Peer-to-Peer (P2P) file-sharing networks.  In this session, you will be introduced to Alpha60, an ongoing research project with six years of TV and film distribution data that reveals trends and oddities in global media desire.  The speakers will present data on the quantity, timing, and location of downloads for major television series and films, offering data on unofficial global audienceship and speculating on new insights about cultural circulation, transnational belonging, and fandom.
    • AI Transcript

  77. (2025)  Cracking Enigma: A Chronology of Cryptographic Breakthroughs  - Brais Macknik-Conde  
    • The Enigma machine was a sophisticated encryption device used by Nazi Germany during World War II.  Its mechanical design utilized three rotors that scrambled plaintext into complex ciphertext, with additional layers of security from unique internal settings.  However, inherent weaknesses and poor operational procedures left it vulnerable to cryptanalysis.  The first successful attacks on Enigma were conducted by Polish mathematicians in the early 1930s.  By exploiting repeating message indicators and rotor cycle patterns, they deduced rotor wirings and constructed replica Enigma machines.  Their breakthroughs enabled systematic decryption until German countermeasures in 1938 forced new approaches.  Alan Turing and his team at Bletchley Park refined these methods, pioneering statistical techniques and mechanical computation to accelerate decryption.  Techniques such as Banburismus and the Good-Turing estimation method were created under Turing's leadership.  The development of the Bombe machine allowed rapid elimination of incorrect rotor settings, enabling the Allies to decipher vast amounts of enemy communication.  This presentation will focus on history and cryptography, examining how breaking Enigma provided critical intelligence that shaped Allied strategies and shortened the war by an estimated two years, saving millions of lives in one of humankind's most significant intelligence operations.
    • AI Transcript

  78. (2025)  Hacking for Social Justice  - Danacea Vo  
    • "How can my hacking skills become a force for advancing social justice?"  Those who ponder this question often know what they're up against - oppression, inequality, enjewification...  But the path toward building meaningful change can feel unclear or overwhelming.  This talk draws from years of experience working alongside activists, human rights defenders, and digital organizers, and offers a practical framework for lasting, meaningful change.  You'll gain social impact strategies that will help you align your technical skills with the movements and communities you care about.  If you've ever felt the call to do more - with purpose, with clarity, with community - this is your invitation.
    • AI Transcript

  79. (2025)  Communication and Movement in Internet Shutdown Protests: Rethinking Mesh Messaging  - Cora Rowena Ruiz  
    • 2024 was the worst year for Internet shutdowns ever recorded, with nearly 296 documented events across 54 countries.  Frequently imposed during protests and times of unrest, shutdowns are commonly used as a tactic to suppress dissent and restrict communication.  Mesh messaging is widely hailed as a potential workaround, yet these tools are generally considered unreliable, untrusted, and ultimately go unused.  Mesh systems depend heavily on the spatial relationships between nodes, but existing research on how people move and communicate in protest settings is sparse.  This talk explores a holistic approach to mesh tool design, grounded in qualitative firsthand experiences to build effective blackout-resistant mesh tools.
    • Understanding Communication Dynamics and Needs during Protests amid Internet Shutdowns
    • AI Transcript

  80. (2025)  Expanding BioArtBot Color Palette - A Beginner's Guide to Lab Automation & Biosafety  - Danny Chan  
    • BioArtBot.org is a project for encouraging curiosity in microbiology and lab automation through creative expression.  It is an open-source project built on a pipetting robot that draws user submitted pixel art by placing colored bacteria on agar.  Using the story of the BioArtBot development as a guide, this talk will provide a basic overview of the technologies (hardware, software, and wetware) implemented in the BioArtBot.  It will describe how lab automation is used in biotech companies, how it might be used by amateur/community investigators, and how the BioArtBot is an interesting framework to contribute to if you are looking to skill-up in lab automation.  It will also describe how the living pigments for this project were created and sourced, how you might create/source your own, and the amazing diversity of living chemical refineries that are bacteria.  So if you're interested in robots and bacteria, come find out how we can command our tireless inorganic creations to deposit aesthetically pleasing arrangements of the ancient form-factor of all life.
    • AI Transcript

  81. (2025)  RDP Spray and Pray: Research on Modern RDP Attacks From Spray to Exploit  - Tessa Mishoe  
    • RDP has been around the block for a while.  Since 1998, admins shudder at the mere mention of port 3389.  It's anything but old-hat, though - even today, there are a lot of active attack methods and adaptations for the modern world.  This talk will be going through the world of RDP attacks from the perspective of an attacker, a defender, and us - the researchers and engineers.  Some mass RDP attack data will be showcased, along with how to identify, label, and further prevent these attacks in the future.
    • AI Transcript

  82. (2025)  The Trials and Tribulations of Building Your Own Phone  - Wesley Appler (lamemakes)  
    • Over the last two decades digital surveillance has become baked into our daily lives.  Your current and past location, who you're in contact with, habits/interests, sensor data, and a trove of other personal information is constantly being sent to third-parties by the smartphone that is nearly always carried on us.  What would it look like if we reconsidered the mobile phone entirely, putting extra emphasis on privacy and intentional disconnection via open-source hardware and software?  This talk will follow Wesley's journey to do just that, starting at the conception of the idea, getting acquainted with mobile networks/operators, obtaining proprietary datasheets, designing hardware, failed/successful prototypes, the current state of the project (along with demos), and how any interested parties can get involved.
    • Slides
    • AI Transcript

  83. (2025)  ATM Hacking: Past and Present  - Roman Pushkin  
    • This talk explores the evolution of ATM hacking, from classic physical attacks to modern software exploits, using two real-world case studies.  Roman will demonstrate how cybercriminals bypass security measures and why banks often stay silent.  Attendees will see a live demo of a custom "flusher device" built for a tabletop coin dispenser (reverse-engineered from eBay), highlighting vulnerabilities in cash-handling systems.
    • AI Transcript

  84. (2025)  Exploiting Emergent Property-Based Vulnerabilities in Large Language Models  - David Kuszmar  
    • As AI technology expands across both benign and malicious applications, our understanding of the attack surface must evolve to account for emergent properties in complex systems.  In large language models, these emergent behaviors create novel classes of vulnerabilities that are not only unpatched, but largely unrecognized.  By systematically manipulating the model's limited perception of reality, attackers can induce cascading failures that go far beyond traditional filter bypasses, exposing fundamental weaknesses in the internal logic and contextual binding of these systems.  This session will unpack how these vulnerabilities work, walk through real examples, and explore the far-reaching implications for AI security, governance, and safety.
    • AI Transcript

  85. (2025)  How I Used and Abused LLMs to Get Top 250 on HTB  - Rambo Anderson-You  
    • This talk explores an experiment in giving AI system-wide access to compete on Hack The Box (HTB).  The talk details the development of a semiautonomous workflow for Capture the Flag (CTF) competitions, involving jailbreaks, LLM switching, and hardware.  Through iterative diagrams, the talk traces how the workflow evolved as the AI improved at capturing flags.  This presentation considers how this CTF solving AI slop might extend to real-world scenarios like penetration testing, red teaming, and bug bounty hunting.
    • AI Transcript

  86. (2025)  Planning a Project That Has No Budget  - Travis Southard  
    • Projects are notoriously hard for developers to manage even with project managers, budget limits, and deadlines.  Often in hacking and civic tech, we are our own PMs, funders, and timekeepers, which means projects can simultaneously have no budget and unlimited budget.  Since a community is not paying for a particular feature, they have no "I think we've reached where we want to stop spending" moment, so when is something done?  It doesn't cost our coworkers to ask for more features, so when are they asking too much?  Travis will talk about his experiences as a professional nonprofit legal aid developer and as a volunteer project lead to explore what's helped him when working with nebulous conditions around specific requirements.
    • AI Transcript

  87. (2025)  The Struggle for Connection in a Fragmented World: Rebuilding Third Spaces  - Jack Gangi  
    • Third spaces - those vital, informal gathering places between home and work - have long been central to hacker culture, but they're vanishing.  This talk will explore why third spaces matter more than ever for connection, creativity, and counterculture, and how we can rebuild them in a world increasingly fragmented by gentrification, digital monopolies, and social isolation.  From hackerspaces to IRC to local meetups, Jack will trace our roots and offer ideas for rekindling authentic community, both online and off.
    • AI Transcript

  88. (2025)  Eternal Soup  - Jackson Hillmer, Nicole Davis, Gabe Marquez  
    • Eternal Soup is an experimental band born in Jersey City, New Jersey.  With an intent on exploring a wide array of musical concepts in different mediums, the trio has developed an adaptive nature for communicating with their growing audience.  Jackson Hillmer's simmering groove of pops and cracks supports Nicole Davis' amorphous vocals, fresh trumpet playing, and electronics to shape a fragrant atmosphere.  Guitarist and sonic scientist Gabe Marquez slips, slides, and chops up melodies you only just heard, but feel you should've written.  From avant-garde arts cafes and overflowing local bars to family friendly barn shows, Eternal Soup explores and elevates the fundamental concept that each flavor in a recipe must be enhanced with the next ingredient thrown in the pot.
    • AI Transcript

  89. (2025)  Neon Edge  - Scott Burgert
    • Neon Edge will take the stage to reimagine hidden cosmic records as rhythmic sonic artifacts by putting together songs from scratch in front of the audience.  Accompanied by live-programmed visuals, the performance will become an immersive journey that pushes beyond the conventional boundaries of music and sound.  In addition to the performance, Neon Edge will also be hosting a discussion on his creation and production process.  He will be talking about how the live show and visuals merge and how he works on writing and producing his music.
    • AI Transcript

  90. (2025)  A History of Music: From Handel to House  - Randy Naraine  
    • Randy Naraine will play 30 minutes of music on piano starting from 1729 and ending in the year 2025 in a single medley.  Each song will flow into the next one, passing through various styles, decades, composers, and musicians.  Randy was a music teacher before working in cyber.  Exposing students to various styles of music was one of the most fulfilling parts of that job.  He hopes to recreate this on stage.  (The medley song list will be shared via QR onstage.)  For the last part of the performance, Randy will take shoutouts from the audience of different themes, emotions, styles, tempos, etc., and try to do a live improvisation of three pieces based on the most common suggestions.  Randy is the manager of cybersecurity engineering at JetBlue Airways, based in Queens.  He has been to 91 countries and all 50 states, often traveling with a MIDI controller to create music based on surroundings in every corner of the Earth.  He is passionate about cybersecurity, particularly defense automation, security data analytics, aircraft security, human exploits and defenses, and digital forensics.  He plays around New York City at various venues throughout the year and loves to perform while interacting with the public.  He believes music and the arts are needed to balance the often intense world of cybersecurity and technology.
    • AI Transcript

  91. (2025)  H4X0R5 - Live Hardware Remix & Rescore  - Videopunks
    • They're trashing our rights!!  All-hardware A/V band Videopunks have stripped the original score from the classic 1995 movie (while leaving the dialog and sound effects), cut the film down to an hour (all killer, no filler!), and have written a brand new score on the Roland MC-707 to be performed LIVE for the original film's 30th anniversary.  Grooveboxes, VCRs, and a whole lot of cables - come see your favorite movie of all time in a brand new way right before your eyes!  Hack the Planet!!  Since 2010, Videopunks have focused on analog video hardware, performing alongside artists such as Merzbow, Machine Girl, NMESH, and literally hundreds of others.  With VXPX, they've released over 60 DIY VHS releases of audiovisual madness from over 100 video artists, including a VHS version of H4X0R5.  In 2024, they toured the live score project in over a dozen cities, including Tokyo!
    • H4X0R5  Remixed & Rescored by Videopunks

  92. (2025)  LEX the Lexicon Artist  - LEX the Lexicon Artist
    • LEX the Lexicon Artist is a rapper-songwriter who blends hip-hop, pop, punk, and a distinctly nerdy eccentricity.  Whether in recorded music or live shows, LEX's humor, candidness, authenticity, and over-the-top stage presence have captured the hearts of fans around the world.  LEX has performed in 34 U.S. states and in Canada.  They have been an official musical guest at various anime and gaming conventions, including Music and Gaming Festival (MAGFest) in National Harbor, MD; FanimeCon in San Jose, CA; SXSW Music Festival in Austin, TX; Anime Expo in Los Angeles, CA; CyphaCon in Lake Charles, LA; and ColossalCon East in Poconos, PA.  LEX has also performed at major colleges and universities, including UC Davis, San Francisco State University, and Stanford University.  LEX has released two full length albums - Alter Ego (2020) and Raging Ego (2018) - as well as a variety of singles and EPs.  Their work has been featured on the actual play RPG podcast Campaign: Skyjacks (One Shot Podcast Network) and the Firefox documentary series Firefox Presents.  In 2025, LEX received full funding of the Kickstarter campaign for their third full-length album, Toxpsychology.

  93. (2025)  HOPE_16 Closing Ceremonies  - Evil Corley
    • Nothing lasts forever and that even applies to HOPE (the conference, not the concept).  We will reminisce about what happened this weekend as if it was a decade ago.  And we can guarantee there will be many fun stories to share.  If you're really lucky, you'll get to help us clean up!
    • AI Transcript



HOPE 26







Knowledge is Power

Return to $2600 Index